CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
Why the CISA KEV Catalogue Matters for Your InfrastructureWhen the US Cybersecurity and Infrastructure Security Agency (CISA) adds a vulnerability to...
Why the CISA KEV Catalogue Matters for Your Infrastructure
When the US Cybersecurity and Infrastructure Security Agency (CISA) adds a vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue, it is not a theoretical warning. It means attackers are already using that flaw in real campaigns. For system administrators and managed service providers in Spain, from Barcelona to Lleida, this list is a practical prioritisation tool: if a vulnerability appears there, delaying patches can quickly turn into a security incident.

On 26 August 2026, CISA expanded the KEV catalogue with six vulnerabilities, spanning widely used technologies such as Citrix NetScaler, the Linux kernel, Microsoft SQL Server, and components common in Red Hat environments and .NET applications. This update offers a clear snapshot of what threat actors are targeting right now, and it serves as a reminder that even older flaws can resurface when organisations fail to apply updates.
The Most Urgent Entry: Citrix NetScaler CVE-2026-8452
The newest vulnerability in this batch is CVE-2026-8452, which affects Citrix NetScaler ADC and NetScaler Gateway. This flaw involves a memory issue that can lead to denial of service, but technical analyses also describe scenarios where remote code execution is possible without authentication. Citrix released patches on 30 June 2026, and CISA has set a deadline of 29 August 2026 for federal agencies to apply mitigations. However, the urgency extends well beyond government networks.
Observations from active campaigns show that attackers exploiting CVE-2026-8452 often deploy a web shell to maintain persistence and run reconnaissance commands to map the internal network. On a perimeter appliance like NetScaler, such post-exploitation activity can easily lead to lateral movement and credential theft. If your organisation uses NetScaler as a VPN gateway or AAA virtual server, you should treat this as a critical priority.
Other Vulnerabilities in the KEV Update
The remaining five vulnerabilities are older but still dangerous because they continue to be exploited in the wild. CVE-2019-1068 affects Microsoft SQL Server and allows remote code execution in the context of the service account. Given the high privileges that SQL Server service accounts often hold, this can give attackers access to sensitive data and other resources.
CVE-2022-0995 is a Linux kernel vulnerability that enables a local user to escalate privileges or cause a denial of service. This is particularly risky on multi-user servers or systems where an attacker has already gained an initial foothold. CVE-2021-23758 is a deserialisation vulnerability in Ajax.NET Professional, which can lead to code execution if an application exposes vulnerable endpoints. Rounding out the list are CVE-2015-3246, a race condition in Red Hat libuser, and CVE-2015-5287, a privilege escalation in Red Hat ABRT.
Practical Steps for System Administrators
For defenders, the message is clear: start with a thorough but practical inventory. Identify all instances of NetScaler, Linux servers, SQL Server deployments, applications using Ajax.NET Professional, and Red Hat systems with libuser or ABRT. Then prioritise patching, beginning with systems exposed to the internet and those most critical to your operations.
For NetScaler, update to the patched versions and verify that the device does not retain vulnerable configurations or states, especially if it acts as an AAA virtual server or VPN gateway. Also, check for signs of intrusion: web shells, enumeration commands, or any unusual activity in logs. For SQL Server, apply the patch and monitor engine telemetry for code execution under the service account. Reducing the attack surface while remediation is underway is also wise.
For Linux systems, update the kernel where there is a real risk of local privilege escalation. Strengthen privilege controls and integrity monitoring until the patch is fully deployed. Remember that the KEV deadline is set for US federal agencies, but many organisations worldwide use it as a benchmark for a simple reason: if a vulnerability is being actively exploited, every day of delay increases the likelihood of a breach.
How Centralised Protection Can Help
Managing patches across multiple servers can be overwhelming, especially when you need to respond quickly to alerts like this KEV update. A centralised security approach can simplify the process. For example, ALMC.es offers Abuse Shield, a service that centralises server protection by automatically blocking malicious IPs, managing fail2ban across multiple machines, and sharing a reputation feed among all your servers. This kind of solution helps you respond faster to threats and reduces the window of exposure.
By combining timely patching with proactive IP blocking and reputation monitoring, you can significantly lower the risk of falling victim to these exploited vulnerabilities. Whether you are a hosting company or a small business with your own servers, taking a layered defence approach is essential in today's threat landscape.
Related
- Citrix NetScaler RCE: CISA Orders Urgent Patching
- Citrix NetScaler CVE-2026-8452: Act Now to Shield Your Edge
- Citrix NetScaler RCE: CISA Orders Urgent Patching
- Desarrollo web
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
