Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six newly exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway. The additions follow a report from Cisco Talos, which detailed a Chinese cybercrime group targeting Windows and Linux web servers globally. CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes by specific deadlines, highlighting the ongoing threat posed by these vulnerabilities and the importance of addressing underlying weaknesses during software development.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six newly exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog.CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, has been added.CVE-2026-8452, an improper restriction of operations within a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway, has been added.Other newly added vulnerabilities include CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758.CISA is urging Federal Civilian Executive Branch agencies to apply fixes for the added vulnerabilities by specific dates.The analysis of CVE records reveals that injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025.Organizations must remain vigilant and proactive in order to protect against exploitation, as the cybersecurity landscape is constantly evolving.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added six newly exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, a move that is expected to have significant implications for organizations across various sectors. The additions, which were made on Wednesday, August 27, 2026, bring the total number of known exploited vulnerabilities listed in the KEV catalog to six.
Among the newly added vulnerabilities are CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. Additionally, CVE-2026-8452, an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway, has been added to the catalog. This vulnerability could lead to a denial-of-service, a type of attack where an attacker intentionally overwhelms a system with a large amount of traffic in order to make it unavailable to users.
Other newly added vulnerabilities to the KEV catalog include CVE-2022-0995, an out-of-bounds memory write vulnerability in the Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system. Furthermore, CVE-2015-5287, a privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, has been added to the catalog.
In addition to these vulnerabilities, CVE-2015-3246, a race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation, has also been added to the catalog. Lastly, CVE-2021-23758, a deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes, has been added to the catalog.
According to CISA, the addition of these six new vulnerabilities to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. This report highlights the ongoing threat posed by these vulnerabilities and the importance of applying fixes to protect against exploitation.
In response to the recent additions, CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026. The agency also stresses that threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence (AI) is being used to automate exploitation efforts.
The analysis of CVE records from 2024 and 2025 by CISA reveals that injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025. This finding underscores the importance of addressing the underlying weaknesses that often translate directly into real-world exploitation. By reducing these root causes during software development, providers can help prevent vulnerabilities that are more likely to be targeted by threat actors.
The addition of these six new vulnerabilities to the KEV catalog highlights the importance of staying informed about the latest security threats and vulnerabilities. It also serves as a reminder that the cybersecurity landscape is constantly evolving, and that organizations must remain vigilant and proactive in order to protect against exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/US-Cybersecurity-Agency-Adds-Six-Newly-Exploited-Flaws-to-KEV-Catalog-Warns-of-Active-Exploitation-Efforts-ehn.shtml
https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html
https://nvd.nist.gov/vuln/detail/CVE-2019-1068
https://www.cvedetails.com/cve/CVE-2019-1068/
https://nvd.nist.gov/vuln/detail/CVE-2026-8452
https://www.cvedetails.com/cve/CVE-2026-8452/
https://nvd.nist.gov/vuln/detail/CVE-2022-0995
https://www.cvedetails.com/cve/CVE-2022-0995/
https://nvd.nist.gov/vuln/detail/CVE-2015-5287
https://www.cvedetails.com/cve/CVE-2015-5287/
https://nvd.nist.gov/vuln/detail/CVE-2015-3246
https://www.cvedetails.com/cve/CVE-2015-3246/
https://nvd.nist.gov/vuln/detail/CVE-2021-23758
https://www.cvedetails.com/cve/CVE-2021-23758/
Published: Sat Aug 29 22:18:05 2026 by llama3.2 3B Q4_K_M