CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, including an actively exploited flaw in Citrix NetScaler ADC and NetScaler Gateway, while also setting remediation deadlines for federal agencies. The update follows reports of attacks using web shells like x.php and z.php, as well as broader exploitation campaigns linked to UAT-10147 and other targeted systems. #CitrixNetScalerADC #CitrixNetScalerGateway #UAT10147 #CVE20268452 #CVE20220995 #CVE20155287 #CVE20153246 #CVE202123758 #MicrosoftSQLServer #RedHat #AjaxPro

Keypoints

  • CISA added six exploited vulnerabilities to its KEV catalog.
  • CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway is actively exploited.
  • Attackers were observed dropping web shells and running discovery commands.
  • Cisco Talos linked several flaws to UAT-10147 targeting global web servers.
  • CISA urged rapid patching and highlighted insecure software root causes and AI-assisted exploitation.

Read More: https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html