Mastodon Mastodon Mastodon Mastodon

CISA Flags Citrix NetScaler Bug and Five Other CVEs in KEV

Photo of author

CyberSecureFox Editorial Team

Published:

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, 2026. At the center of the update is CVE-2026-8452, a vulnerability in Citrix NetScaler ADC and NetScaler Gateway related to improper restriction of operations within the bounds of a memory buffer. The remaining five CVEs affect Microsoft SQL Server, the Linux kernel, Red Hat components, and the Ajax.NET Professional library. Organizations using these products must immediately assess their exposure and prioritize the installation of fixes—for two of the vulnerabilities, the remediation deadline for U.S. federal agencies has already passed.

List of vulnerabilities and technical details

The six added vulnerabilities cover a wide range of products and classes of defects—from remote code execution to privilege escalation:

  • CVE-2026-8452 — improper restriction of operations within the bounds of a memory buffer in Citrix NetScaler ADC and NetScaler Gateway. According to the description, the vulnerability can lead to denial of service. The source material characterizes it as high severity; however, a confirmed CVSS score was not yet available at the time of publication.
  • CVE-2019-1068 — a remote code execution vulnerability in Microsoft SQL Server that allows an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account.
  • CVE-2022-0995 — an out-of-bounds write in the Linux kernel that can allow a local user to gain elevated privileges or cause denial of service.
  • CVE-2015-5287 — privilege escalation in the Red Hat Automatic Bug Reporting Tool (ABRT) via a symbolic link attack on a file with a predictable name.
  • CVE-2015-3246 — a race condition in Red Hat libuser that allows an authenticated local user to corrupt the /etc/passwd file, which can lead to denial of service or privilege escalation.
  • CVE-2021-23758 — deserialization of untrusted data in Ajax.NET Professional (AjaxPro), allowing remote code execution via arbitrary .NET classes.

Notably, the list includes vulnerabilities ranging in age from a few months to more than ten years (CVE-2015-3246 and CVE-2015-5287 date back to 2015). This underscores a persistent trend: attackers continue to successfully exploit long-known flaws that remain unpatched in production environments.

Impact assessment and affected organizations

Organizations using Citrix NetScaler ADC and NetScaler Gateway face the greatest immediate risk. These products are widely deployed in corporate networks for load balancing, application delivery, and remote access. The CVE-2026-8452 vulnerability in these products is formally described as leading to denial of service; however, its inclusion in the KEV catalog indicates that CISA has evidence of real-world exploitation.

The vulnerabilities in the Linux kernel (CVE-2022-0995) and Red Hat components (CVE-2015-5287, CVE-2015-3246) pose a threat to Linux-based server infrastructures, especially in educational institutions, media companies, and the technology sector. CVE-2021-23758 in AjaxPro affects .NET-based web applications, while CVE-2019-1068 impacts Microsoft SQL Server instances. Public information on methods used to exploit CVE-2019-1068 in real-world attacks is reportedly not available at this time.

Context: CISA report on root causes of vulnerabilities

The KEV catalog update coincided with the publication of CISA’s vulnerability review, in which the agency analyzed the root causes of insecure software. According to this review, injection-class defects became the largest category, with a reported 7,701 CVEs in 2024 and 21,019 CVEs in 2025. CISA also notes that vulnerabilities related to memory safety and improper input validation appear in the KEV catalog disproportionately often compared with the overall CVE population for fiscal years 2024 and 2025.

The agency separately pointed out that adversaries are using artificial intelligence to automate the exploitation of vulnerabilities—a trend that increases the speed at which mass attacks follow CVE publication.

Remediation deadlines and practical recommendations

Under a CISA directive, Federal Civilian Executive Branch (FCEB) agencies were required to remediate CVE-2019-1068 and CVE-2026-8452 by August 29, 2026—a deadline that has already passed. For the remaining four vulnerabilities (CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, CVE-2021-23758), the deadline is set for September 9, 2026.

Recommended actions for organizations of all types:

  1. Inventory affected products. Check your infrastructure for Citrix NetScaler ADC/Gateway, Microsoft SQL Server, systems based on the Linux kernel, Red Hat ABRT, libuser, and applications using AjaxPro.
  2. Patch prioritization. CVE-2026-8452 and CVE-2019-1068 require immediate attention. For NetScaler, follow Citrix guidance to upgrade to fixed versions.
  3. Audit Linux servers. For CVE-2022-0995, ensure the kernel has been updated to a version containing the fix. For CVE-2015-5287 and CVE-2015-3246, check ABRT and libuser package versions—despite the age of these vulnerabilities, outdated RHEL/CentOS systems may still be exposed.
  4. Review .NET web applications. If AjaxPro is used in your projects, update the library or isolate vulnerable components.
  5. Monitoring. Configure detection for exploitation attempts at the perimeter, paying particular attention to anomalous requests to NetScaler and unusual activity on web servers.

The addition of six vulnerabilities to the KEV catalog—from the recent CVE-2026-8452 to flaws dating back to 2015—demonstrates that the age of a vulnerability does not reduce its danger as long as unprotected systems exist. Organizations should first address CVE-2026-8452 in Citrix NetScaler and CVE-2019-1068 in SQL Server, for which the CISA-mandated deadline has already passed, and then, by September 9, remediate the remaining four flaws in the Linux kernel, Red Hat components, and AjaxPro.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.