HomeSecurityCISA KEV: 6 new vulnerabilities – NetScaler, Linux, SQL Server

CISA KEV: 6 new vulnerabilities – NetScaler, Linux, SQL Server

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) list , including critical vulnerabilities affecting Citrix NetScaler ADC , Linux Kernel , and Microsoft SQL Server . CISA confirmed that there is evidence of active exploitation for these vulnerabilities, urging organizations to implement the fixes immediately. The addition comes at a time of increased activity by Chinese cybercriminal groups targeting servers worldwide.

CISA KEV vulnerability list NetScaler Linux SQL Server 2026

The KEV list is one of CISA ’s most trusted tools for informing organizations about vulnerabilities that are actively being exploited by malicious actors. Whenever a vulnerability is added to the list, U.S. federal agencies are required to implement the necessary updates within a specific deadline . However, the list’s importance extends far beyond the public sector, as it serves as a guide for any organization that wants to protect itself from real-world threats.

The six vulnerabilities added cover a wide range of technologies — from databases and operating systems to web application development tools. This demonstrates that attackers are not focusing on a single point of weakness, but are opportunistically exploiting any loophole they find in exposed systems.

CISA KEV: Analysis of the six new vulnerabilities

The first vulnerability, CVE-2019-1068, affects Microsoft SQL Server and allows an attacker to execute code under the SQL Server Database Engine service account. This is a vulnerability Remote Code Execution (RCE) that still poses a threat to unpatched systems. It is worth noting that there is no public information on how to exploit it.

See also: CISA: Citrix NetScaler vulnerability in KEV Catalog

The second vulnerability, CVE-2026-8452, is the most recent and affects Citrix NetScaler ADC and NetScaler Gateway. It is an “improper restriction of operations within the bounds of a memory buffer” vulnerability, which can lead to a denial-of-service (DoS). Defused Cyber ​​and Previdian (formerly KEVIntel) have already warned of active exploitation attempts. According to Previdian, attackers install web shells named “x.php” and “z.php,” executing commands such as “id” and “echo” to map the target environment.

Telemetry data reveals that 36 exploit attempts in the last 12 days, originating from 12 unique IP addresses of attackers from countries including Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Turkey, the US, and Vietnam. The geographic spread of the attacks suggests organized and coordinated activity.

CISA KEV - SecNews.gr

The third vulnerability, CVE-2022-0995 , concerns the Linux Kernel and specifically an out-of-bounds memory write error that allows a local user to gain privileged access or cause a denial of service . Privilege escalation vulnerabilities in the Linux Kernel are particularly dangerous in cloud and containerized infrastructure environments, where an attacker who has already gained initial access can escalate their privileges.

Vulnerabilities CVE-2015-5287 and CVE-2015-3246 concern the Red Hat Linux ecosystem . The first is a privilege escalation vulnerability in the Red Hat Automatic Bug Reporting Tool (ABRT) , which allows local users with specific privileges to gain higher privileges via a symlink attack on a file with a predictable name. The second concerns a race condition vulnerability in the Red Hat libuser library , which allows an authenticated local user to corrupt the /etc/passwd file , causing DoS or privilege escalation. Despite their age (2015), these vulnerabilities still pose a threat to systems that have not been patched.

The sixth vulnerability, CVE-2021-23758, affects Ajax.NET Professional (AjaxPro) and allows Remote Code Execution via deserialization of untrusted data. Deserialization vulnerabilities are particularly dangerous as they can lead to complete system takeover.

See also: CISA to federal agencies: Fix Citrix NetScaler and Chrome zero-days immediately

CISA KEV and the connection with the Chinese group UAT-10147

The addition of CVE-2022-0995 , CVE-2015-5287 , CVE-2015-3246 , and CVE-2021-23758 to the KEV list is directly related to a report by Cisco Talos , which revealed the activities of a Chinese cybercrime group known as UAT-10147 . This group targets Windows and Linux web servers worldwide, with a focus on the education, media, technology, and gaming sectors.

UAT -10147 is a prime example of modern cybercriminal activity that combines old, known vulnerabilities with modern exploitation techniques. The use of vulnerabilities dating back to 2015 shows that many organizations neglect to apply key security updates, leaving the door open to attackers. This highlights the importance of a comprehensive patch management.

CISA warns of critical vulnerabilities in Microsoft, VMware, Apple, KEV

CISA has set specific deadlines for the Federal (FCEB): vulnerabilities CVE-2019-1068 and CVE-2026-8452 must be addressed by August 29, 2026, while the remaining four must be addressed by September 9, 2026.While these deadlines primarily apply to US government agencies, they are a clear signal to every organization worldwide.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Meanwhile, CISA has published a new vulnerability review that examines the root causes of insecure software. According to an analysis of CVE records for 2024 and 2025 , injection vulnerabilities emerged as the most dominant category, with 7,701 CVEs in 2024 and an explosive increase to 21,019 CVEs in 2025. The agency also highlighted that malicious actors are now using artificial intelligence (AI) to automate exploitation efforts.

Practical steps to protect against CISA KEV vulnerabilities

For organizations using Citrix NetScaler ADC or NetScaler Gateway, immediate application of available patches is imperative, given the active exploitation of CVE-2026-8452. It is also recommended to monitor logs for suspicious activity, especially the presence of PHP files named “x.php” or “z.php” in unexpected locations, as these are characteristic signs of a web shell installation.

For Linux, especially those based on Red Hat or derivative distributions, keeping the Linux Kernel and system libraries up-to-date is essential. Implementing the principle of least privilege — that is, granting users only the privileges they need — can significantly reduce the impact of privilege escalation vulnerabilities. In addition, using Endpoint Detection and Response (EDR) can help detect suspicious activity early.

See also: Citrix NetScaler: 6 vulnerabilities allow file read and DoS

CVE-2026-58644 Microsoft SharePoint zero-day vulnerability CISA KEV

For applications that use AjaxPro or similar .NET libraries , replacing or updating to more secure versions is the only effective solution. vulnerabilities Deserialization are particularly difficult to address with other security measures, as they exploit fundamental mechanisms of the runtime environment. In general, every organization should maintain an up-to-date asset inventory and regularly monitor the CISA KEV list for new additions.

Overall, the latest update to the KEV list is a stark reminder that old vulnerabilities remain dangerous when not addressed in a timely manner. The increasing use of AI by malicious actors to automate attacks, combined with the active activity of groups like UAT-10147, makes timely patching and adopting a proactive security posture more critical than ever. According to The Hacker News, CISA continues to actively monitor developments and update the KEV list with new threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS