Security NEXTAugust 27, 2026🇯🇵Translated from Japanese

CISA Adds Six Known Exploited Vulnerabilities Affecting NetScaler ADC, Linux Kernel and Microsoft SQL Server to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively exploiting them in real-world attacks.

Only one of the newly listed issues was disclosed in 2026. CVE-2026-8452 resides in NetScaler ADC and NetScaler Gateway, products widely used for application delivery and VPN connectivity. The flaw stems from improper memory handling and can cause a denial-of-service condition on devices with specific configurations.

The other five vulnerabilities were originally published in 2022 or earlier. CVE-2022-0995 affects the Linux Kernel event notification subsystem known as watch_queue. A local attacker can perform an out-of-bounds memory write, potentially overwriting kernel structures to gain elevated privileges or trigger a denial of service.

Red Hat products are also impacted. CVE-2015-5287 in the Automatic Bug Reporting Tool (ABRT) and CVE-2015-3246 in the libuser library both allow local privilege escalation. The libuser flaw can additionally corrupt the password file, leading to service disruption.

CISA continues to track exploitation of these issues and recommends that organizations apply vendor patches without delay and review system configurations to reduce exposure.

Related articles

Security NEXTVulnerabilities & Exploits

Cisco Pre-Announces Security Advisories and Patches for Multiple Products on September 2, 2026

Cisco Systems has disclosed plans to publish security advisories for several product lines on September 2, 2026. The advisories will cover vulnerabilities affecting IP telephony devices, network switches, and email security appliances. Targeted products include Cisco IOS XR Software, multiple series of Cisco Desk Phones, Nexus 9000 Series switches with Silicon One, and Cisco Secure Email. The company will also provide updates aimed at strengthening security in IOS XR. No CVE identifiers, vulnerability details, affected versions, or CVSS scores have been released at the pre-notification stage. Cisco strongly recommends applying the forthcoming fixes once they become available, while noting that the schedule and product scope may still change.

BoletimSecVulnerabilities & Exploits

Zscaler Fixes Multiple Critical Flaws in Client Connector Enabling RCE and Authentication Bypass

Zscaler has released patches for several vulnerabilities in its Client Connector agent that could lead to remote code execution, authentication bypass, local privilege escalation, and denial of service. The most severe issue, tracked as CVE-2026-59568 with a CVSS score of 9.1, allows unauthenticated remote attackers to execute arbitrary code within the context of the Zscaler Client Connector process. A second critical flaw, CVE-2026-59564 also rated CVSS 9.1, affects communication between the connector and its management portal, enabling attackers to circumvent authentication mechanisms. Additional vulnerabilities include a local buffer overflow on Android and ChromeOS tracked as CVE-2026-59566 with CVSS 8.4, as well as issues that could result in privilege escalation or service disruption. The flaws impact Client Connector versions across Windows, macOS, Linux, iOS, Android, and ChromeOS, with varying affected builds depending on the platform. Updated builds for lines 4.6 through 4.9 on Windows and equivalent fixes for other operating systems are now available.

HabrVulnerabilities & Exploits

Out of 48,000 Vulnerabilities Only 1% Are Dangerous: How to Find Them Using CVSS 4.0, EPSS, KEV and FSTEC Methodology

The article explains why prioritizing vulnerabilities is critical in 2025-2026 as exploitation became the top initial access vector for the first time in 19 years according to Verizon DBIR. It details the limitations of CVSS scoring alone, the shift to CVSS 4.0 with new metrics like Attack Requirements and Supplemental Metrics, and the impact of NIST reducing NVD enrichment to only actively exploited or federal software cases. EPSS provides daily exploitation probability predictions using machine learning on over 1,100 features, while CISA KEV and the new LEV metric help identify confirmed or likely exploited vulnerabilities. The text covers practical prioritization criteria including asset significance, exploit availability, and network exposure, plus challenges for Russian infrastructure due to CVE dependency. It also compares CISA KEV with commercial catalogs like VulnCheck KEV that detect exploitation earlier.

Security NEXTVulnerabilities & Exploits

Google Releases Chrome 152 Fixing 327 Vulnerabilities Including 10 Critical Flaws

Google has released Chrome 152 for Windows, macOS, and Linux, addressing a total of 327 security vulnerabilities. Ten of these issues received the highest severity rating of Critical. The update resolves multiple Use After Free flaws in core components such as ANGLE, Aura, and Chromecast. Specific CVEs fixed include CVE-2026-79282 in ANGLE and several others in Aura and Chromecast modules. The release targets memory corruption and input validation weaknesses that could lead to remote code execution. Users are strongly advised to apply the update immediately to mitigate potential exploitation risks.