CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws
CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, 2026, confirming active exploitation in the wild and elevating patching urgency for organizations running Citrix NetScaler, Microsoft SQL Server, Linux systems, and Red Hat components.
The most time-sensitive entry is CVE-2026-8452, a memory-related flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to denial of service and, according to technical analysis, unauthenticated remote code execution. Citrix published fixes on June 30, 2026, and CISA mandated federal agencies to apply mitigations or updates by August 29, 2026. Attackers have already used the vulnerability to plant web shells for persistence and run reconnaissance commands, enabling lateral movement and credential theft on perimeter appliances.
The remaining five vulnerabilities include long-standing issues that continue to appear in campaigns:
- CVE-2019-1068 in Microsoft SQL Server, allowing remote code execution under the database engine service account.
- CVE-2022-0995 in the Linux kernel, enabling local privilege escalation or denial of service on multi-user systems.
- CVE-2021-23758, an unsafe deserialization flaw in Ajax.NET Professional that can result in code execution when exposed endpoints are present.
- CVE-2015-3246, a race condition in Red Hat libuser.
- CVE-2015-5287, a privilege escalation issue in Red Hat ABRT.
Defenders are advised to conduct targeted inventories of exposed NetScaler devices, SQL Server instances, Linux servers, applications using Ajax.NET Professional, and Red Hat systems with libuser or ABRT. Priority remediation should begin with internet-facing systems, followed by verification of patch application, removal of residual vulnerable configurations, and monitoring for web shells or anomalous service-account activity.
Related articles
LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings
Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.
Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing
The number of vulnerabilities in web applications continues to grow each quarter, driven in part by the rapid adoption of artificial intelligence in software development pipelines. While integrating AI tools boosts productivity and shortens release cycles, many organizations fail to match this speed with equivalent security testing and validation processes. As a result, increasing amounts of code reach production environments without ever being assessed from an attacker’s perspective. Cybercriminals have quickly recognized this gap, exploiting repeated flaw patterns in applications that skip security reviews. The article emphasizes that pentesting must become a recurring part of the development cycle, conducted weekly or monthly to match the pace of updates. Continuous security testing allows teams to identify and remediate issues before they can be weaponized. Developing rapidly with AI is not inherently risky, but releasing unvalidated code transforms speed into exposure.
Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access
Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.