CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Summary

CISA has added six exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Among these is a high-severity vulnerability affecting Citrix NetScaler ADC and Gateway, which has been actively exploited.

IFF Assessment

FOE

The inclusion of actively exploited vulnerabilities in the KEV catalog indicates that attackers are successfully compromising systems, posing a direct threat to defenders.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: August 29, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching and mitigating the vulnerabilities added to the KEV catalog, as these are known to be exploited in the wild. Proactive threat hunting and strengthening defenses around affected products like Citrix NetScaler are crucial steps.

Read Full Story →