On August 26, the United States Cybersecurity and Infrastructure Security Agency (CISA) took action by adding six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This decision underscores the agency’s commitment to protecting government entities and critical infrastructure from increasing cyber threats. The vulnerabilities in question have been marked for urgent attention, with calls for rapid remediation from organizations affected by these flaws.
The KEV catalog signifies that CISA has identified evidence of these vulnerabilities being exploited in real-world scenarios, necessitating immediate action. Among the newly listed vulnerabilities, two stand out due to their high-severity ratings, which both carry a Common Vulnerability Scoring System (CVSS) score of 8.8, indicating critical risks associated with their exploitation.
The first vulnerability, designated as CVE-2026-8452, is a memory overflow flaw affecting NetScaler ADC and NetScaler Gateway, products developed by Citrix. This vulnerability was reported by Citrix at the conclusion of June, leading to significant concern given its potential impact. When exploited, this memory overflow issue can result in unpredictable behavior or erroneous system functions, notably causing denial of service (DoS) conditions if the appliance is operated in a Gateway configuration, which includes functions such as SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual server.
To address the threat posed by this vulnerability, Citrix has released patches across several versions. Specifically, updates are available for NetScaler ADC and NetScaler Gateway, including versions 14.1-72.61 and subsequent releases, as well as for the 13.1-63.18 and later versions of 13.1. Additionally, patches have been provided for the FIPS-certified releases of these ADCs and Gateways. This proactive approach aims to mitigate the risks associated with this vulnerability, ensuring that users can protect their systems effectively.
The second high-severity vulnerability, CVE-2019-1068, relates to a remote code execution (RCE) flaw within Microsoft SQL Server, first discovered in 2019. Although a fix has been available for nearly seven years, the inclusion of this vulnerability in the KEV catalog indicates that unscrupulous actors continue to exploit it. By executing specially crafted queries against the vulnerable SQL Server, an attacker can potentially run code under the SQL Server Database Engine service account, creating severe security risks for organizations that have yet to apply the necessary patches.
CISA has encouraged government agencies and other affected entities to prioritize applying patches for both CVE-2026-8452 and CVE-2019-1068 by August 29. This push is part of a broader strategy to reinforce cybersecurity measures across various sectors, particularly as the threat landscape continues to evolve.
Beyond the two high-severity vulnerabilities, CISA also identified four additional flaws, all from previous years, which have also made their way into the KEV catalog. These include CVE-2015-3246, noted for its race condition vulnerability in Red Hat Libuser, which has a CVSS rating of 5.1; CVE-2015-5287, a privilege escalation vulnerability associated with the Red Hat automatic bug reporting tool, rated 7.8; CVE-2021-23758 linked to the Ajax.NET professional framework’s deserialization of untrusted data, rated 8.1; and CVE-2022-0995, an out-of-bounds write vulnerability in the Linux kernel, also rated at 7.8.
CISA has set a deadline for patches related to these additional vulnerabilities, stating that they must be addressed by September 9. This comprehensive listing and the urgency surrounding these vulnerabilities highlight the increasing importance of cybersecurity vigilance in today’s interconnected digital environment.
As cyber threats grow more sophisticated, organizations must remain proactive in their approach to vulnerability management. CISA’s recent announcements serve as a critical reminder of the vigilance required to safeguard sensitive data and maintain the integrity of critical infrastructure amidst a landscape fraught with danger.

