Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Updates KEV Catalog with Six New Vulnerabilities

CISA Updates KEV Catalog with Six New Vulnerabilities

Posted on August 27, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, incorporating six new security flaws. This move, announced on Wednesday, highlights vulnerabilities in Citrix NetScaler ADC, NetScaler Gateway, and other widely used software, emphasizing the need for heightened security measures.

Highlighted Vulnerabilities in the KEV Catalog

The newly listed vulnerabilities include CVE-2019-1068, a remote code execution flaw in Microsoft SQL Server, and CVE-2026-8452, which affects Citrix NetScaler ADC and NetScaler Gateway, potentially causing denial-of-service conditions. Another is CVE-2022-0995, an out-of-bounds write vulnerability in the Linux Kernel that could allow local privilege escalation or system disruption.

Additionally, CVE-2015-5287 and CVE-2015-3246 pose risks in Red Hat systems, where privilege escalation could occur due to symlink attacks and race conditions, respectively. CVE-2021-23758 in Ajax.NET Professional allows remote code execution through untrusted data deserialization, marking it as a significant threat.

Active Exploitation Alerts and Global Impact

Security experts from Defused Cyber and Previdian have noted active exploitation attempts related to CVE-2026-8452, with attackers deploying web shells such as ‘x.php’ and ‘z.php’ and executing discovery commands. These activities have been traced to 12 unique IP addresses from various countries, including Switzerland, Germany, and the U.S.

Moreover, a report by Cisco Talos reveals that a Chinese cybercrime group, UAT-10147, has targeted these vulnerabilities, particularly affecting sectors like education and technology. This global reach underscores the urgent need for organizations to enhance their cybersecurity protocols.

Urgent Recommendations and Future Outlook

CISA has urged Federal Civilian Executive Branch (FCEB) agencies to implement fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, with the remaining vulnerabilities requiring action by September 9, 2026. This directive comes as CISA releases a comprehensive review focusing on the root causes of software insecurity.

With injection weaknesses leading the CVE categories in recent years, CISA highlights the importance of addressing fundamental security flaws. The use of artificial intelligence in automating exploits further emphasizes the need for robust preventative measures in software development.

By tackling these core issues, software providers can reduce vulnerabilities that are frequently targeted by malicious actors, thereby enhancing overall security resilience. CISA’s ongoing efforts aim to mitigate risks and protect critical infrastructure from evolving cyber threats.

The Hacker News Tags:CISA, cyber attacks, Cybersecurity, Exploitation, KEV, Linux kernel, NetScaler, security flaws, SQL Server, Vulnerabilities

Post navigation

Previous Post: Critical Fix for Adobe Campaign Classic Vulnerabilities
Next Post: GPUThor Attack Bypasses ECC on NVIDIA GPUs

Related Posts

Ubuntu Security Flaw CVE-2026-3888 Enables Root Access Ubuntu Security Flaw CVE-2026-3888 Enables Root Access The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
How AI-Enabled Workflow Automation Can Help SOCs Reduce Burnout How AI-Enabled Workflow Automation Can Help SOCs Reduce Burnout The Hacker News
NGINX Vulnerability CVE-2026-42945 Actively Exploited NGINX Vulnerability CVE-2026-42945 Actively Exploited The Hacker News
Ubuntu Snap-confine Vulnerability Risks Root Access Ubuntu Snap-confine Vulnerability Risks Root Access The Hacker News
New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Windows Backdoor SLEEPWALKER Evades Detection
  • US Halts Chinese Hacking Tools Targeting Infrastructure
  • GPUThor Attack Bypasses ECC on NVIDIA GPUs
  • CISA Updates KEV Catalog with Six New Vulnerabilities
  • Critical Fix for Adobe Campaign Classic Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Windows Backdoor SLEEPWALKER Evades Detection
  • US Halts Chinese Hacking Tools Targeting Infrastructure
  • GPUThor Attack Bypasses ECC on NVIDIA GPUs
  • CISA Updates KEV Catalog with Six New Vulnerabilities
  • Critical Fix for Adobe Campaign Classic Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark