CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation affecting Citrix NetScaler ADC and Gateway, Microsoft SQL Server, Ajax.NET Professional, the Linux kernel, Red Hat ABRT, and Red Hat libuser. The additions include CVE-2026-8452, a high-severity NetScaler memory-buffer vulnerability reportedly used for web-shell deployment and reconnaissance activity; internet-facing NetScaler appliances, SQL Server instances, and applications using Ajax.NET Professional are priority targets for exposure review, patching, and compromise hunting.
The older Linux and Red Hat vulnerabilities can enable local privilege escalation following an initial compromise, increasing their operational significance despite their age. CISA directed U.S. federal civilian agencies to remediate CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and the other four KEV entries by September 9; organizations should similarly prioritize remediation according to confirmed exploitation, internet exposure, asset criticality, and potential business impact.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-8452, CVE-2019-1068, CVE-2021-23758, CVE-2015-3246, CVE-2015-5287, and CVE-2022-0995 to its Known Exploited Vulnerabilities Catalog after identifying evidence of active exploitation. The flaws affect Citrix NetScaler, Microsoft SQL Server, Ajax.NET Professional, Red Hat libuser and ABRT, and the Linux kernel.
Citrix disclosed CVE-2026-8452, a memory-overflow vulnerability affecting NetScaler ADC and Gateway appliances, and released fixes in versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. Citrix said at disclosure that it had not observed unmitigated exploitation.
WatchTowr research indicated that the NetScaler memory-overflow flaw CVE-2026-8452 may permit unauthenticated remote code execution. Exploitation requires vulnerable firmware and an appliance configured with a NetScaler Gateway or AAA virtual server.
Open-source reporting cited by the Guyana National CIRT indicated that CVE-2026-8451, affecting Citrix NetScaler products, was being exploited. The reference also reiterated that CVE-2026-8452 was exploited in the wild.
Brazil's CTIR Gov issued ALERTA 76/2026 concerning the actively exploited Microsoft SQL Server vulnerability CVE-2019-1068, which can permit arbitrary code execution. The alert urged organizations, including those in Brazil's REGIC network, to identify affected deployments and immediately apply vendor security updates.
CISA directed U.S. Federal Civilian Executive Branch agencies to remediate the Microsoft SQL Server and Citrix NetScaler vulnerabilities by August 29, 2026, and the Linux kernel, Red Hat ABRT, Red Hat libuser, and Ajax.NET Professional vulnerabilities by September 9, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
11 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcecirt.gy
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.