CVE Tools

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker NewsBy The Hacker News

Reported exploitedCitrix NetScaler ADCCitrix NetScaler Gateway

Our summary

CISA has updated its Known Exploited Vulnerabilities catalog with six critical flaws affecting major enterprise infrastructure, including a denial-of-service issue in Citrix NetScaler ADC/Gateway (CVE-2026-8452). The list also includes remote code execution bugs in Microsoft SQL Server (CVE-2019-1068) and Ajax.NET Professional (CVE-2021-23758), alongside kernel and privilege escalation vulnerabilities in the Linux Kernel (CVE-2022-0995), Red Hat ABRT (CVE-2015-5287), and Red Hat libuser (CVE-2015-3246).

Security researchers have observed active exploitation of the Citrix flaw, where attackers deploy PHP web shells and execute discovery commands from multiple countries. These additions follow Cisco Talos reporting on a Chinese cybercrime group targeting global server ecosystems, prompting federal agencies to remediate the highest-priority items by August 29, 2026.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store