ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. CISA KEV Update: Six Actively Exploited Flaws...
  • All articles
  • Categories
  • Tags
  • Statuses

CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server

Why the CISA KEV Catalogue Matters for Your InfrastructureWhen the US Cybersecurity and Infrastructure Security Agency (CISA) adds a vulnerability to...

Why the CISA KEV Catalogue Matters for Your Infrastructure

When the US Cybersecurity and Infrastructure Security Agency (CISA) adds a vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue, it is not a theoretical warning. It means attackers are already using that flaw in real campaigns. For system administrators and managed service providers in Spain, from Barcelona to Lleida, this list is a practical prioritisation tool: if a vulnerability appears there, delaying patches can quickly turn into a security incident.

Server room with red alert dots on racks and a glowing shield icon above a central server

On 26 August 2026, CISA expanded the KEV catalogue with six vulnerabilities, spanning widely used technologies such as Citrix NetScaler, the Linux kernel, Microsoft SQL Server, and components common in Red Hat environments and .NET applications. This update offers a clear snapshot of what threat actors are targeting right now, and it serves as a reminder that even older flaws can resurface when organisations fail to apply updates.

The Most Urgent Entry: Citrix NetScaler CVE-2026-8452

The newest vulnerability in this batch is CVE-2026-8452, which affects Citrix NetScaler ADC and NetScaler Gateway. This flaw involves a memory issue that can lead to denial of service, but technical analyses also describe scenarios where remote code execution is possible without authentication. Citrix released patches on 30 June 2026, and CISA has set a deadline of 29 August 2026 for federal agencies to apply mitigations. However, the urgency extends well beyond government networks.

Observations from active campaigns show that attackers exploiting CVE-2026-8452 often deploy a web shell to maintain persistence and run reconnaissance commands to map the internal network. On a perimeter appliance like NetScaler, such post-exploitation activity can easily lead to lateral movement and credential theft. If your organisation uses NetScaler as a VPN gateway or AAA virtual server, you should treat this as a critical priority.

Other Vulnerabilities in the KEV Update

The remaining five vulnerabilities are older but still dangerous because they continue to be exploited in the wild. CVE-2019-1068 affects Microsoft SQL Server and allows remote code execution in the context of the service account. Given the high privileges that SQL Server service accounts often hold, this can give attackers access to sensitive data and other resources.

CVE-2022-0995 is a Linux kernel vulnerability that enables a local user to escalate privileges or cause a denial of service. This is particularly risky on multi-user servers or systems where an attacker has already gained an initial foothold. CVE-2021-23758 is a deserialisation vulnerability in Ajax.NET Professional, which can lead to code execution if an application exposes vulnerable endpoints. Rounding out the list are CVE-2015-3246, a race condition in Red Hat libuser, and CVE-2015-5287, a privilege escalation in Red Hat ABRT.

Practical Steps for System Administrators

For defenders, the message is clear: start with a thorough but practical inventory. Identify all instances of NetScaler, Linux servers, SQL Server deployments, applications using Ajax.NET Professional, and Red Hat systems with libuser or ABRT. Then prioritise patching, beginning with systems exposed to the internet and those most critical to your operations.

For NetScaler, update to the patched versions and verify that the device does not retain vulnerable configurations or states, especially if it acts as an AAA virtual server or VPN gateway. Also, check for signs of intrusion: web shells, enumeration commands, or any unusual activity in logs. For SQL Server, apply the patch and monitor engine telemetry for code execution under the service account. Reducing the attack surface while remediation is underway is also wise.

For Linux systems, update the kernel where there is a real risk of local privilege escalation. Strengthen privilege controls and integrity monitoring until the patch is fully deployed. Remember that the KEV deadline is set for US federal agencies, but many organisations worldwide use it as a benchmark for a simple reason: if a vulnerability is being actively exploited, every day of delay increases the likelihood of a breach.

How Centralised Protection Can Help

Managing patches across multiple servers can be overwhelming, especially when you need to respond quickly to alerts like this KEV update. A centralised security approach can simplify the process. For example, ALMC.es offers Abuse Shield, a service that centralises server protection by automatically blocking malicious IPs, managing fail2ban across multiple machines, and sharing a reputation feed among all your servers. This kind of solution helps you respond faster to threats and reduces the window of exposure.

By combining timely patching with proactive IP blocking and reputation monitoring, you can significantly lower the risk of falling victim to these exploited vulnerabilities. Whether you are a hosting company or a small business with your own servers, taking a layered defence approach is essential in today's threat landscape.

Related

  • Citrix NetScaler RCE: CISA Orders Urgent Patching
  • Citrix NetScaler CVE-2026-8452: Act Now to Shield Your Edge
  • Citrix NetScaler RCE: CISA Orders Urgent Patching
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Server Management & Monitoring
Process Automation (Scripts and Bots)
Process Automation Scripts and Bots
Full Stack Web Development Laravel, Vue.js
Monitoring & Incident Response (SIEM)
Relacionados
  • GeoServer CVE-2024-36401: Act Fast to Shield Your Servers
    Cybersecurity · 13 minutes ago
  • SharePoint Server Critical Flaw: Immediate Steps to Secure Your Farm
    Cybersecurity · 13 minutes ago
  • VMware vCenter CVE-2026-59310: Urgent Patch Guide for EU Admins
    Cybersecurity · 13 minutes ago
  • Guard Your Code: The GhostSplice MCP Attack and How to Stay Safe
    Cybersecurity · 13 minutes ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 1 hour ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Replicate FLUX.1 Kontext [Max]
    Development
  • CData Connect Cloud
    Database
  • Akamai MCP Server
    Cloud Service
  • Prompt for User Input MCP Server
    Communication
  • Bucket
    Official 🌟 Oficial
  • Aegis-SSH-MCP
    Other
  • DeepSeek MCP Server
    Development
  • Adobe After Effects MCP
    Development
  • APIMesh
    Web Scraping
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar