Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

OpenAI: Hugging Face Incident a “Warning Shot” to the World

August 27, 2026

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

August 27, 2026

Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Inf

August 27, 2026
Facebook X (Twitter) Instagram
Friday, August 28
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix
Cyber Security

CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix

Team-CWDBy Team-CWDAugust 27, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The US Cybersecurity and Infrastructure Security Agency (CISA) added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.

CISA KEV listing means the US agency has found evidence of exploitation in the wild.

The August 26 list included two high-severity security vulnerabilities.

The first, tracked as CVE-2026-8452, is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.

It was reported by Citrix at the end of June and attributed a severity rating (CVSS) of 8.8.

Exploiting the flaw can lead to unpredictable or erroneous behavior and denial of service (DoS) if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Citrix has provided a patch in the following updates:

  • NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP

The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.

Despite a patch having been available for seven years, the KEV addition shows threat actors are still actively exploiting the flaw in unpatched systems.

Exploiting this vulnerability involves submitting a specially crafted query to an affected SQL server. It can allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CISA urged government agencies to apply patches for both vulnerabilities by August 29.

Other vulnerabilities added to the CISA KEV catalog on August 26, all several-year-old flaws, must be patched by September 9, the US agency said.

They include:

  • CVE-2015-3246: Red Hat Libuser race condition vulnerability (CVSS rating: 5.1)
  • CVE-2015-5287: Red Hat automatic bug reporting tool privilege escalation vulnerability (CVSS rating: 7.8)
  • CVE-2021-23758: Ajax.NET professional deserialization of untrusted data vulnerability (CVSS rating: 8.1)
  • CVE-2022-0995 Linux kernel out-of-bounds write vulnerability (CVSS rating: 7.8)

Image credits: Pavel Kapysh / JHVEPhoto / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWhy everyone is a viable target for fraud
Next Article Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Team-CWD
  • Website

Related Posts

Cyber Security

Your Firewall Benchmarks Are Reassuring, That’s the Problem

August 27, 2026
Cyber Security

Four in Five AI Tools Run with No IT Oversight, Research Finds

August 26, 2026
Cyber Security

Australia Warns of Active Exploitation of Critical TeamCity Server Fla

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.