CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA has added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in Citrix NetScaler, Linux Kernel, and Microsoft SQL Server, urging federal agencies to patch them immediately.
Intelligence analysis by Gemini 2.5 Flash

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently updated its KEV catalog with six new vulnerabilities, highlighting active exploitation of these flaws. Among them are a high-severity vulnerability in Citrix NetScaler ADC and Gateway, an out-of-bounds memory write in the Linux Kernel, and a remote code execution flaw in Microsoft SQL Server, with federal agenci…
Imagine there's a list of secret doors that bad guys know how to open in computer systems. CISA, a government group that helps keep computers safe, just added six more of these secret doors to their special list because bad guys are actually using them right now! These doors are in popular computer programs like those used by big companies and even the internet itself. CISA is telling everyone, especially government computers, to quickly lock these doors with a special patch before more bad guys sneak in.
Analysis
The U.S. Cybersecurity and Infrastructure Security Agency's (CISA) recent addition of six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog underscores a persistent challenge in cybersecurity: the active exploitation of known, often older, software flaws. This move serves as a critical alert, particularly for Federal Civilian Executive Branch (FCEB) agencies, which are mandated to address these vulnerabilities within tight deadlines. The inclusion of these flaws, some dating back to 2015, highlights that even long-identified weaknesses remain viable targets for sophisticated threat actors, emphasizing the importance of rigorous patch management and continuous monitoring.
CISA's KEV Catalog
CISA's KEV catalog is a definitive list of vulnerabilities that have been observed in active exploitation, making it an essential resource for organizations to prioritize their patching efforts. The agency's analysis of CVE records from 2024 and 2025 revealed that injection weaknesses and memory safety issues disproportionately appear in KEVs compared to the broader CVE population. This finding reinforces CISA's message to software providers about the necessity of addressing fundamental weaknesses during development, as these often directly translate into real-world exploitation scenarios. The catalog's updates are a direct response to intelligence gathered from various security researchers and telemetry data, providing actionable insights for defenders.
CVE-2026-8452
One of the most pressing vulnerabilities added is CVE-2026-8452, an improper restriction of operations within a memory buffer flaw affecting Citrix NetScaler ADC and NetScaler Gateway, which can lead to denial-of-service. Security firms like Defused Cyber and Previdian have specifically warned about active exploitation attempts targeting this vulnerability. Telemetry data indicates at least 36 exploitation attempts over a 12-day period from 12 unique attacker IP addresses across multiple countries, including Switzerland, Germany, and the U.S. Attackers have been observed deploying web shells and executing discovery commands, signaling initial access and reconnaissance efforts within compromised systems. This highlights the immediate threat posed by this particular flaw.
UAT-10147
The broader context of these additions is further illuminated by a report from Cisco Talos, detailing the activities of a Chinese cybercrime group identified as UAT-10147. This group is actively targeting Windows and Linux web servers globally, impacting diverse sectors such as education, media, technology, and gaming. While not all newly added KEVs are directly linked to UAT-10147, the group's modus operandi of exploiting known flaws aligns with CISA's observations about threat actors leveraging simple, persistent vulnerabilities. The agency also noted the increasing use of artificial intelligence (AI) to automate exploitation efforts, suggesting a future where the speed and scale of attacks could significantly increase, making timely patching even more critical.
Key points
- CISA added six actively exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux Kernel, and Microsoft SQL Server.
- Federal Civilian Executive Branch (FCEB) agencies are mandated to apply fixes for critical flaws by August 29, 2026, and others by September 9, 2026.
- CVE-2026-8452, a Citrix NetScaler vulnerability, is under active exploitation with attackers deploying web shells.
- A Chinese cybercrime group, UAT-10147, is targeting Windows and Linux web servers across various sectors.
- CISA's analysis indicates injection weaknesses and memory safety issues are disproportionately found in actively exploited vulnerabilities.
CISA's proactive identification and cataloging of actively exploited vulnerabilities, coupled with strict patching deadlines for federal agencies, can significantly improve the nation's cybersecurity posture. By providing clear guidance and highlighting root causes, CISA empowers organizations to prioritize remediation efforts and encourages software providers to build more secure products from the outset, potentially reducing the overall attack surface.
Despite CISA's warnings, the persistent exploitation of known and often older vulnerabilities suggests that many organizations struggle with timely patching and robust security hygiene. The increasing use of AI by threat actors to automate exploitation could accelerate attacks, making it harder for defenders to keep pace and leaving critical infrastructure vulnerable to widespread compromise.



