The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
The vulnerabilities are listed below –
CVE-2019-1068 – A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2026-8452 – An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
CVE-2022-0995 – An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
CVE-2015-5287 – A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name.
CVE-2015-3246 – A race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
CVE-2021-23758 – A deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes.
The development comes as both Defused Cyber and Previdian (formerly KEVIntel) warned of active exploitation efforts aimed at CVE-2026-8452. “The attackers were dropping a web shell named ‘x.php’ and ‘z.php,’ and running discovery commands, like ‘id’ and ‘echo,’” Previdian said in a LinkedIn post.
Telemetry data shows that 36 exploitation attempts have been detected over the past 12 days from 12 unique attacker IP addresses from Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam.
The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
There is currently no public information on how CVE-2019-1068 is being exploited in the wild. CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
The additions also coincide with CISA’s release of a new vulnerability review that delves into the root causes of insecure software and the practical steps organizations can take to remedy them and prevent exploitation.
According to the agency’s analysis of CVE records from 2024 and 2025, injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025. CISA also stressed that threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence (AI) is being used to automate exploitation efforts.
“In FY2024 and FY2025, memory safety and improper input validation weaknesses appear disproportionately in KEVs compared to the full CVE population,” CISA said.
“For software providers, this finding underscores the importance of addressing the underlying weaknesses that often translate directly into real‑world exploitation. By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors.”
📰 Original Source:TheHackerNews ✍️ Author: info@thehackernews.com (The Hacker News)
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Leave a Reply