TL;DR
CISA added six exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 26, 2026. The list spans a Citrix NetScaler flaw, a Microsoft SQL Server bug, two Red Hat issues, a Linux kernel write flaw, and an Ajax.NET defect. Each entry carries evidence of active exploitation, so federal agencies face firm remediation deadlines.
- Product: NetScaler ADC, Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)
- Vulnerabilities: 2 flaws (CVE-2026-8452, CVE-2019-1068)
- Highest severity: 9.8 (High · CVSSv3)
- Worst impact: Memory overflow leading to unpredictable or erroneous behavior and Denial of Service
- Status: 2 exploited; patches available
- Action: Update to 72.61, 63.18, 37.272 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-8452 | 9.8 | Memory overflow leading to unpredictable or erroneous behavior and Denial of Service | 72.61, 63.18, 37.272 | Exploited |
| CVE-2019-1068 | 8.8 | NVD-CWE-noinfo | — | Exploited |
Why It Matters
These six exploited vulnerabilities give attackers a mix of remote code execution, privilege escalation, and denial of service. Perimeter devices like Citrix NetScaler sit directly on the internet, so a single flaw can expose an entire network. CISA lists these bugs because threat actors already use them in real attacks. Government teams must patch fast, and private defenders should treat the catalog as a priority list.
How the Attacks Work
The mechanisms differ across the batch. CVE-2026-8452 is a memory overflow in NetScaler ADC and Gateway that triggers erroneous behavior and denial of service on Gateway or AAA virtual servers. CVE-2019-1068 lets a remote attacker run code through mishandled internal SQL Server functions.
CVE-2022-0995 is an out-of-bounds write in the Linux kernel watch_queue subsystem, which can overwrite kernel state for local privilege escalation. CVE-2021-23758 allows unsafe deserialization in the Ajax.NET Professional library, enabling remote code execution. The two Red Hat bugs, CVE-2015-3246 and CVE-2015-5287, abuse a libuser race condition and an ABRT symlink flaw for local privilege gains.
Affected Versions
Citrix confirmed CVE-2026-8452 affects NetScaler ADC and Gateway on the 14.1 and 13.1 branches, per advisory CTX696604. The libuser flaw hits versions before 0.56.13-8 and 0.60 before 0.60-7. The ABRT bug affects releases before 2.7.1. All package versions of ajaxpro.2 are vulnerable. The Linux kernel issue reached mainline builds before the fix commit landed.
Patch and Mitigation Steps
Apply vendor fixes now. Citrix ships patched NetScaler builds 14.1-72.61 and 13.1-63.18 and later. Red Hat and Linux distributions offer updates for the libuser, ABRT, and kernel flaws. Microsoft published guidance for the SQL Server bug, and Ajax.NET users should remove or replace the library. Researchers have published proof-of-concept code for the Linux kernel and NetScaler flaws, so speed matters.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!