CISA adds six actively exploited flaws to critical vulnerability list

The U.S. Cybersecurity and Infrastructure Security Agency added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 27, 2026, including remote code execution flaws in Citrix NetScaler (CVE-2026-8452), Microsoft SQL Server (CVE-2019-1068), and a Linux kernel out-of-bounds write (CVE-2022-0995). The Citrix flaw was exploited in the wild within 12 days of proof-of-concept release.

3 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 CISA added 6 actively exploited flaws to its KEV catalog: MS SQL Server RCE (CVE-2019-1068), Citrix NetScaler buffer overflow (CVE-2026-8452), Linux kernel OOB write (CVE-2022-0995), plus Red Hat A

mastodon:infosec-exchangeother33d ago kagi ↗

🤖 CISA added 6 actively exploited flaws to its KEV catalog: MS SQL Server RCE (CVE-2019-1068), Citrix NetScaler buffer overflow (CVE-2026-8452), Linux kernel OOB write (CVE-2022-0995), plus Red Hat ABRT, libuser and Ajax.NET RCE. 🔗 https:// thehackernews.com/2026/08/cisa -adds-six-exploited-flaws-to-kev.html # CVE # CyberSec # InfoSec # RCE

CISA orders federal agencies to patch exploited Citrix, Linux bugs

kite:cybersecurityother33d ago kagi ↗

The U.S. Cybersecurity and Infrastructure Security Agency added actively exploited vulnerabilities in Citrix NetScaler, Linux and other products to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to meet remediation deadlines [bleepingcomputer.com#1][cybersecuritynews.com#1][cybersecuritynews.com#2][thehackernews.com#1][helpnetsecurity.com#1][heise.de#1]. The Citri

CISA added six CVEs to the KEV catalog, including a Citrix NetScaler pre-auth RCE actively exploited within 12 days of PoC release, and a Microsoft SQL Server flaw https:// deafnews.it/en/article/cisa

mastodon:infosec-exchangeother33d ago kagi ↗

CISA added six CVEs to the KEV catalog, including a Citrix NetScaler pre-auth RCE actively exploited within 12 days of PoC release, and a Microsoft SQL Server flaw https:// deafnews.it/en/article/cisa-ad ds-six-cves-to-kev-from-citrix-rce-to-sql-server-with-seven-years-of-attacks