CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog Including Citrix NetScaler, Linux Kernel and Microsoft SQL Server Flaws
CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, 2026, confirming active exploitation in the wild and elevating patching urgency for organizations running Citrix NetScaler, Microsoft SQL Server, Linux systems, and Red Hat components.
The most time-sensitive entry is CVE-2026-8452, a memory-related flaw in Citrix NetScaler ADC and NetScaler Gateway that can lead to denial of service and, according to technical analysis, unauthenticated remote code execution. Citrix published fixes on June 30, 2026, and CISA mandated federal agencies to apply mitigations or updates by August 29, 2026. Attackers have already used the vulnerability to plant web shells for persistence and run reconnaissance commands, enabling lateral movement and credential theft on perimeter appliances.
The remaining five vulnerabilities include long-standing issues that continue to appear in campaigns:
- CVE-2019-1068 in Microsoft SQL Server, allowing remote code execution under the database engine service account.
- CVE-2022-0995 in the Linux kernel, enabling local privilege escalation or denial of service on multi-user systems.
- CVE-2021-23758, an unsafe deserialization flaw in Ajax.NET Professional that can result in code execution when exposed endpoints are present.
- CVE-2015-3246, a race condition in Red Hat libuser.
- CVE-2015-5287, a privilege escalation issue in Red Hat ABRT.
Defenders are advised to conduct targeted inventories of exposed NetScaler devices, SQL Server instances, Linux servers, applications using Ajax.NET Professional, and Red Hat systems with libuser or ABRT. Priority remediation should begin with internet-facing systems, followed by verification of patch application, removal of residual vulnerable configurations, and monitoring for web shells or anomalous service-account activity.
Related articles
Next.js Patches Two Critical RCE Vulnerabilities in Versions 15.5.24 and 16.3.3
Next.js has released security updates to address two critical vulnerabilities that could allow unauthenticated remote code execution. The fixes are available in versions 15.5.24 and 16.3.3. The first issue, tracked as CVE-2026-75604 with a CVSS score of 9.0, affects applications hosted on Windows servers using Pages Router or App Router without Cache Components and stems from a path traversal flaw. The second vulnerability impacts the Image Optimization API when processing malicious AVIF files, enabling code execution through crafted image inputs. Both flaws affect a wide range of versions from 10.0.0 and 13.4 onward. Administrators are advised to update immediately, rebuild containers, and verify production environments run the patched releases, especially on Windows systems and those handling user-uploaded images.
Multiple Vulnerabilities Found in Apache Tomcat, Four Rated Critical by CISA
Apache Tomcat has received updates addressing 11 vulnerabilities across versions 11.0.25, 10.1.59, and 9.0.121. The Apache Software Foundation rated four issues as Important, while CISA assigned Critical severity to four CVEs based on CVSS v3.1 scores reaching 9.8. The flaws include authentication bypasses, access control evasion due to path evaluation order, off-by-one errors, and HTTP/2 resource leaks leading to denial of service. One vulnerability was disclosed earlier in July, with the remaining ten detailed on August 25. Moderate and Low severity issues were also patched in the same releases. The discrepancies in severity ratings between the vendor and CISA highlight differing risk assessments for the same CVEs.
SonicWall Patches Critical Path Traversal and Update Flaws in NetExtender for Linux
SonicWall has released fixes for two high-severity vulnerabilities in its NetExtender client for Linux that could allow remote attackers to write arbitrary files with root privileges and manipulate the automatic update process. The flaws impact versions 10.3.5 and earlier, while the Windows version remains unaffected. CVE-2026-66152 carries a CVSS score of 8.8 and stems from improper handling of tar archives containing OPSWAT data, enabling path traversal that lets attackers escape the intended extraction directory. CVE-2026-66153 scores 7.0 and arises from inadequate symlink and temporary file handling in the NEService update mechanism. Both issues require user interaction to exploit, and no in-the-wild attacks have been observed so far. Administrators are urged to upgrade immediately to version 10.3.6 or later, as no workarounds exist.
Redis Patch Bypass Enables Multiple RCE Exploits as PoCs for TLS and Stream Vulnerabilities Go Public
Multiple remote code execution vulnerabilities have been disclosed in Redis over the past month, including a critical patch bypass for CVE-2026-25243 that reintroduces Double Free flaws via crafted stream operations. The latest issue, QVD-2026-58458 affecting the TLS pending list, now has full technical details and a working PoC available, following the earlier QVD-2026-55651 disclosure. All three flaws impact nearly every production version still in use, from Redis 6.2.22 and below through 7.4.9 and 8.6.4. Although authentication is required, widespread weak or empty password configurations and exposed instances make exploitation trivial for attackers. Successful compromise grants arbitrary code execution in the Redis process context, enabling standard post-exploitation steps such as credential harvesting and lateral movement across internal networks. Organizations are urged to inventory all instances, apply the latest patches immediately, restrict network access via ACLs, and monitor for anomalous use of commands like XGROUP, EVAL, and RESTORE.