CISA KEV Catalog Update: Six Actively Exploited Vulnerabilities
First seen Aug 27, 2026 · Updated Aug 27, 2026
CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, spanning Red Hat Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler ADC/Gateway. BOD 26-04 mandates FCEB agencies prioritize rapid remediation of these on internet-facing assets, particularly those allowing full post-exploitation control. All organizations, including those hosting AI infrastructure, are encouraged to remediate promptly given confirmed in-the-wild exploitation.
Technical Analysis
The catalog additions include CVE-2015-3246 (Red Hat Libuser race condition), CVE-2015-5287 (ABRT privilege escalation), CVE-2019-1068 (Microsoft SQL Server RCE via Adaptive Query Processing feature), CVE-2021-23758 (Ajax.NET Professional insecure deserialization enabling RCE), CVE-2022-0995 (Linux Kernel watch_queue out-of-bounds write enabling privilege escalation), and CVE-2026-8452 (Citrix NetScaler ADC/Gateway memory buffer flaw enabling RCE or DoS). Several of these vulnerabilities (SQL Server RCE, deserialization flaw, kernel privilege escalation, and NetScaler buffer overflow) can grant attackers full control of a host, which is especially dangerous for servers running RAG pipelines, LLM inference backends, or agent orchestration frameworks since compromise could lead to exfiltration of API keys, model weights, or vector database contents used by AI agents. Organizations running self-hosted LLM services or agent tool-execution environments on Linux/Windows hosts with SQL Server backends or exposed NetScaler gateways face elevated risk if these systems interface with agent infrastructure. Exploitation of the Linux kernel or NetScaler vulnerabilities could also serve as an initial access or lateral movement vector into networks hosting AI agent deployments, enabling credential theft or supply-chain-style compromise of agent toolchains.
Affected Systems
Red Hat Enterprise Linux (libuser and ABRT packages), Microsoft SQL Server (versions affected by CVE-2019-1068 Adaptive Query Processing feature), Ajax.NET Professional (versions vulnerable to insecure deserialization), Linux Kernel (versions with watch_queue vulnerability, CVE-2022-0995), Citrix NetScaler ADC and NetScaler Gateway (versions affected by CVE-2026-8452 memory buffer flaw)
Indicators of Compromise
- No specific IOCs (hashes/IPs/domains) published in this CISA advisory; organizations should consult vendor advisories and CISA KEV Catalog entries for exploitation indicators.
Remediation Steps
- 1
Patch KEV-listed vulnerabilities immediately
Apply vendor patches for CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, and CVE-2026-8452 on all affected systems, prioritizing internet-facing assets.
- 2
Follow BOD 26-04 guidance
FCEB agencies must comply with remediation timelines under BOD 26-04; other organizations should adopt the same risk-based prioritization voluntarily.
- 3
Check for prior compromise
For high-risk vulnerabilities granting full asset control, verify whether systems were compromised before patches were applied, per BOD 26-04 requirements.
- 4
Audit AI infrastructure exposure
Identify any AI agent, LLM, or RAG infrastructure running on affected Linux, SQL Server, or NetScaler systems and prioritize patching or isolation to prevent credential and API key exposure.
- 5
Restrict Citrix NetScaler exposure
Limit public exposure of NetScaler ADC/Gateway management interfaces and apply Citrix's official mitigation guidance for CVE-2026-8452.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.