CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat, Citrix Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog, warning government agencies and critical infrastructure organizations to patch them quickly.
The KEV listing indicates that CISA has found evidence of exploitation in the wild. Two of the vulnerabilities are high-severity security issues: a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway tracked as CVE-2026-8452, and a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
Citrix has provided patches for the NetScaler ADC and NetScaler Gateway vulnerabilities, but despite a patch being available for seven years, threat actors are still actively exploiting the RCE flaw in unpatched systems.