US CISA Adds Five New Vulnerabilities to Its Catalog Amid Growing Concerns
The US Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog. These include flaws in Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler.
The affected vulnerabilities are CVE-2015-3246, a race condition in Red Hat libuser; CVE-2015-5287, a privilege escalation bug in Red Hat Automatic Bug Reporting Tool; CVE-2019-1068, a remote code execution flaw in Microsoft SQL Server; CVE-2021-23758, a deserialization of untrusted data vulnerability in Ajax.NET Professional; CVE-2022-0995, an out-of-bounds memory write vulnerability in Linux Kernel; and CVE-2026-8452, an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway.
CISA has ordered federal agencies to address these vulnerabilities by September 9, 2026. Private organizations are also recommended to review the catalog and address the vulnerabilities in their infrastructure to protect against attacks exploiting the flaws.