CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerabi...
Read the full advisory on CISA →