Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds Multiple Vulnerabilities to Known Exploited Vulnerabilities Catalog, Urging Immediate Action


U.S. CISA adds five new vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing the importance of prompt action to address these vulnerabilities and prevent potential cyber threats. The newly added vulnerabilities include Red Hat Libuser Race Condition Vulnerability, Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability, Microsoft SQL Server Remote Code Execution Vulnerability, Ajax.NET Professional Deserialization of Untrusted Data Vulnerability, and Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability.

  • Five new vulnerabilities have been added to the CISA KEV catalog, emphasizing the need for prompt action to address them.
  • The newly added vulnerabilities include Red Hat, Microsoft, Ajax.NET, and Citrix vulnerabilities, with some being already observed under active exploitation.
  • CISA has issued a BOD outlining the necessary actions for federal agencies to address the vulnerabilities by specific due dates.
  • Private organizations are also urged to review the CISA catalog and address the vulnerabilities to prevent potential cyber threats.
  • The added vulnerabilities highlight the importance of maintaining up-to-date software and systems to prevent cyber threats.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the importance of prompt action to address these vulnerabilities and prevent potential cyber threats. The newly added vulnerabilities include Red Hat Libuser Race Condition Vulnerability, Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability, Microsoft SQL Server Remote Code Execution Vulnerability, Ajax.NET Professional Deserialization of Untrusted Data Vulnerability, and Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability.

    According to the CISA, the Red Hat Libuser Race Condition Vulnerability (CVE-2015-3246) could allow an authenticated local user to corrupt the /etc/passwd file, leading to a denial of service or escalating privileges. The Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability (CVE-2015-5287) is a privilege escalation bug that could allow local users with certain permissions to gain higher privileges via a symlink attack on a predictable file. The Microsoft SQL Server Remote Code Execution Vulnerability (CVE-2019-1068) is a remote code execution flaw that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

    The Ajax.NET Professional Deserialization of Untrusted Data Vulnerability (CVE-2021-23758) is a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-8452) is an improper restriction of operations within the bounds of a memory buffer vulnerability that could lead to denial-of-service and has been observed under active exploitation in the wild.

    In response to these newly added vulnerabilities, CISA has issued a Binding Operational Directive (BOD) 22-01, which outlines the necessary actions that federal agencies must take to address the identified vulnerabilities by the specified due dates. According to the BOD, federal agencies must address the vulnerabilities in their infrastructure to protect their networks against attacks exploiting the flaws in the catalog.

    Experts are also urging private organizations to review the CISA catalog and address the vulnerabilities in their infrastructure to prevent potential cyber threats. CISA has ordered federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining vulnerabilities must be addressed by September 9, 2026.

    The addition of these new vulnerabilities to the KEV catalog highlights the ongoing importance of maintaining up-to-date software and systems to prevent cyber threats. It is essential for organizations to stay informed and take prompt action to address newly identified vulnerabilities to protect their networks and prevent potential breaches.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Multiple-Vulnerabilities-to-Known-Exploited-Vulnerabilities-Catalog-Urging-Immediate-Action-ehn.shtml

  • https://securityaffairs.com/197975/hacking/u-s-cisa-adds-red-hat-linux-kernel-ajax-net-professional-microsoft-sql-server-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2015-3246

  • https://www.cvedetails.com/cve/CVE-2015-3246/

  • https://nvd.nist.gov/vuln/detail/CVE-2015-5287

  • https://www.cvedetails.com/cve/CVE-2015-5287/

  • https://nvd.nist.gov/vuln/detail/CVE-2019-1068

  • https://www.cvedetails.com/cve/CVE-2019-1068/

  • https://nvd.nist.gov/vuln/detail/CVE-2021-23758

  • https://www.cvedetails.com/cve/CVE-2021-23758/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-8452

  • https://www.cvedetails.com/cve/CVE-2026-8452/


  • Published: Sat Aug 29 23:35:39 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us