Executive Summary
On August 26, 2026, CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, spanning from 2015 to 2026. The vulnerabilities affect critical infrastructure components including Red Hat Libuser, Microsoft SQL Server, Linux Kernel, Ajax.NET Professional, and Citrix NetScaler ADC/Gateway systems. These CVEs enable race condition exploits, privilege escalation, remote code execution, deserialization attacks, memory corruption, and buffer overflow exploits that grant attackers total system control.
This advisory reinforces the urgency of risk-based vulnerability management as federal agencies face increased scrutiny under BOD 26-04, which mandates rapid remediation of KEV-listed vulnerabilities on publicly exposed assets while establishing breach assessment requirements for delayed patching.
Why This Matters Now
The inclusion of a 2026 Citrix vulnerability demonstrates that attackers are rapidly weaponizing zero-day and recently disclosed flaws, while legacy vulnerabilities from 2015-2022 remain unpatched across enterprise networks, creating persistent attack vectors for threat actors targeting critical infrastructure.
Attack Path Analysis
Attackers exploited known vulnerabilities from CISA's KEV catalog to gain initial access through unpatched systems, escalated privileges using kernel exploits and race conditions, moved laterally through unencrypted networks, established command and control channels, and exfiltrated data through unmonitored egress points before causing operational impact.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited publicly known vulnerabilities including CVE-2019-1068 (SQL Server RCE), CVE-2026-8452 (Citrix NetScaler buffer overflow), and CVE-2021-23758 (Ajax.NET deserialization) on internet-facing assets to gain initial foothold
Related CVEs
CVE-2015-3246
CVSS 5.1A race condition vulnerability in Red Hat Libuser allows local users to gain elevated privileges by exploiting timing issues in user account operations.
Affected Products:
Red Hat Libuser – < 0.62-7
Exploit Status:
exploited in the wildCVE-2015-5287
CVSS 7.8A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool allows local users to gain root privileges through improper handling of temporary files.
Affected Products:
Red Hat Automatic Bug Reporting Tool (ABRT) – < 2.1.11-60
Exploit Status:
exploited in the wildCVE-2019-1068
CVSS 8.8A remote code execution vulnerability in Microsoft SQL Server allows an attacker to execute arbitrary code through improper validation of user-supplied data.
Affected Products:
Microsoft SQL Server – 2012 SP4, 2014 SP3, 2016 SP2, 2017, 2019
Exploit Status:
exploited in the wildCVE-2021-23758
CVSS 9.8A deserialization of untrusted data vulnerability in Ajax.NET Professional allows remote attackers to execute arbitrary code through crafted serialized objects.
Affected Products:
Ajax.NET Professional Ajax.NET Professional – < 21.2.17.1
Exploit Status:
exploited in the wildCVE-2022-0995
CVSS 7.8An out-of-bounds write vulnerability in the Linux kernel allows local users to cause denial of service or potentially execute arbitrary code with elevated privileges.
Affected Products:
Linux Linux Kernel – < 5.16.12
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Exploit Public-Facing Application
Impair Defenses: Disable or Modify Tools
Process Injection
Exploitation for Defense Evasion
Exploitation for Credential Access
Exploitation for Client Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST Cybersecurity Framework 2.0 – Threats Associated with Suppliers and Third Parties
Control ID: ID.RA-08
CISA Zero Trust Maturity Model 2.0 – Networks and Systems are Monitored
Control ID: DE.CM-01
PCI DSS 4.0 – Security Vulnerabilities are Identified and Managed
Control ID: 6.3.1
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
EU DORA – Identification and Classification of ICT Risk
Control ID: Article 8
EU NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory remediation under BOD 26-04 for six KEV vulnerabilities including Microsoft SQL Server and Linux Kernel exploits targeting critical infrastructure.
Financial Services
Banking systems using Microsoft SQL Server and Linux environments vulnerable to privilege escalation and remote code execution requiring immediate Zero Trust segmentation implementation.
Health Care / Life Sciences
Healthcare organizations must prioritize patching Citrix NetScaler and SQL Server vulnerabilities to maintain HIPAA compliance and protect encrypted patient data transmission systems.
Information Technology/IT
IT service providers managing multi-cloud environments face elevated risks from memory buffer and deserialization vulnerabilities requiring enhanced egress security and threat detection capabilities.
Sources
- CISA Adds Six Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- National Vulnerability Databasehttps://nvd.nist.gov/Verified
- Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskhttps://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-riskVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the attack blast radius by constraining lateral movement through segmented networks and controlling egress paths. The fabric's identity-aware routing and east-west traffic enforcement could limit attacker reachability across the federal enterprise environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise may still occur through vulnerable internet-facing assets, the CNSF fabric would likely constrain the attacker's ability to reach internal workloads and reduce their operational scope within the compromised environment.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the scope of elevated privileges by limiting administrative access to segmented network zones and reducing the blast radius of compromised credentials across workload boundaries.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain lateral movement by blocking unauthorized inter-workload communication and reducing the attacker's ability to traverse network segments and access additional systems across the environment.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and control mechanisms would likely detect and constrain command and control communications by monitoring traffic patterns and reducing the attacker's ability to maintain persistent channels across the multicloud environment.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration by limiting outbound data flows and reducing the volume of sensitive information that could be extracted through unauthorized channels and destinations.
While some operational impact may remain within compromised segments, the overall blast radius would likely be significantly reduced compared to an unsegmented environment, limiting disruption to isolated network zones.
Impact at a Glance
Affected Business Functions
- Federal IT Infrastructure
- Enterprise Network Security
- Critical System Operations
- Vulnerability Management Programs
Estimated downtime: N/A
Estimated loss: N/A
No direct data exposure reported. This announcement serves as a security advisory for federal agencies and organizations to prioritize patching of actively exploited vulnerabilities that pose significant risk to enterprise environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block known CVE exploit attempts at network boundaries
- • Deploy zero trust segmentation with least privilege policies to prevent lateral movement between workloads and systems
- • Enable encrypted traffic inspection (HPE) with MACsec/IPsec for all east-west and north-south data flows
- • Establish egress security controls with FQDN filtering and policy enforcement to monitor and restrict outbound communications
- • Deploy multicloud visibility and centralized control plane to detect anomalous interactions and maintain unified security posture across hybrid environments



