CISA adds multiple critical vulnerabilities to Known Exploited list

Between 2026-08-26 and 2026-08-27, CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-8452 (Citrix NetScaler ADC/Gateway buffer overflow), CVE-2019-1068 (Microsoft SQL Server RCE), and CVE-2023-49105 (ownCloud authentication bypass). These additions highlight active exploitation of critical infrastructure and cloud platform vulnerabilities.

6 reportsprimary · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

json:cisa-kevprimary34d ago kagi ↗

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements

CVE-2019-1068: Microsoft SQL Server — Microsoft SQL Server Remote Code Execution Vulnerability

json:cisa-kevprimary34d ago kagi ↗

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements

CVE-2023-49105: ownCloud ownCloud — ownCloud Improper Authentication Vulnerability

json:cisa-kevprimary33d ago kagi ↗

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) g

CVE-2026-53362: Linux Kernel — Linux Kernel Unspecified Vulnerability

json:cisa-kevprimary33d ago kagi ↗

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (

CVE-2026-66384: JFrog Artifactory — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

json:cisa-kevprimary33d ago kagi ↗

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL

🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0827 ) CISA has added 3 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother33d ago kagi ↗

🚨 [CISA-2026:0827] CISA Adds 3 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0827 ) CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder