Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Active Exploitation of Six CVEs Across Enterprise Infrastructure

Source context: this article examines information published by the source on August 26, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The affected components and their associated CVEs are:

  • Citrix NetScaler ADC and NetScaler Gateway: CVE-2026-8452 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
  • Microsoft SQL Server: CVE-2019-1068 (Remote Code Execution)
  • Linux Kernel: CVE-2022-0995 (Out-of-Bounds Write)
  • Ajax.NET Professional: CVE-2021-23758 (Deserialization of Untrusted Data)
  • Red Hat Libuser: CVE-2015-3246 (Race Condition)
  • Red Hat Automatic Bug Reporting Tool: CVE-2015-5287 (Privilege Escalation)

Exposure and applicability

These vulnerabilities affect a broad range of infrastructure, from core operating system kernels and database servers to edge networking appliances. The risk is most acute for organizations running these specific versions on publicly exposed assets.

For Federal Civilian Executive Branch (FCEB) agencies, Binding Operational Directive (BOD) 26-04 mandates the prioritization of remediation for KEV Catalog vulnerabilities that grant total control of an asset post-exploitation. While this directive is a federal requirement, the active exploitation status makes these CVEs high-priority targets for any organization utilizing the affected software.

Remediation priorities

Our analysis suggests prioritizing remediation based on asset exposure and potential impact:

  1. Edge Infrastructure: Prioritize Citrix NetScaler ADC and Gateway (CVE-2026-8452) due to their typical position at the network perimeter, which increases the likelihood of external discovery.
  2. Critical Data Stores: Address Microsoft SQL Server (CVE-2019-1068) to prevent remote code execution on systems housing sensitive organizational data.
  3. Core OS and Kernel: Remediate Linux Kernel (CVE-2022-0995) and Red Hat components (CVE-2015-3246, CVE-2015-5287) to prevent privilege escalation or system instability.
  4. Application Frameworks: Update Ajax.NET Professional (CVE-2021-23758) to mitigate risks associated with untrusted data deserialization.

How to validate remediation

Verification must move beyond simple version checks, as a deployed patch does not inherently prove the absence of prior compromise or successful mitigation in all configurations.

  • Configuration Audit: Confirm that patches are applied and that the resulting software versions align with the vendor’s remediated releases.
  • Compromise Assessment: Following BOD 26-04 guidance, defenders should check for indicators of compromise on affected systems before applying patches to ensure they are not locking in a persistent threat actor.
  • Exposure Verification: Use authorized network scanning to confirm that the vulnerable services are no longer reachable or exploitable from untrusted zones.

Limits and open questions

It remains unclear which of these six CVEs specifically grant “total control” of an asset, though BOD 26-04 emphasizes those that do. Additionally, while patching reduces future risk, it does not remediate existing breaches. Residual risk persists if compensating controls (such as network segmentation or WAF rules) are not implemented alongside patches to protect legacy systems that cannot be immediately updated.

Source and editorial note

CISA Adds Six Known Exploited Vulnerabilities to Catalog · Source date: August 26, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment