Cyber Insights: CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalogue

10th September 2026

10th September 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue after evidence emerged that attackers are actively targeting affected systems.
The vulnerabilities span several widely used enterprise technologies, including Citrix NetScaler ADC and Gateway, Microsoft SQL Server, the Linux Kernel, Red Hat components and Ajax.NET Professional. Some date back more than a decade, demonstrating that attackers continue to find value in older vulnerabilities where affected systems remain exposed or unpatched.
The most immediate concern is CVE-2026-8452, affecting Citrix NetScaler infrastructure. Researchers have observed attackers exploiting exposed appliances, deploying PHP web shells and performing reconnaissance on compromised systems.
While CISA’s remediation deadlines apply specifically to U.S. federal agencies, inclusion in the KEV catalogue provides a clear signal to organisations globally that these vulnerabilities should be prioritised for investigation and remediation.
The six vulnerabilities added to CISA’s KEV catalogue affect a mixture of current and legacy enterprise infrastructure.
CVE-2026-8452 – Citrix NetScaler ADC/Gateway
A high-severity memory-handling vulnerability affecting NetScaler infrastructure. Active exploitation has been confirmed, with attackers observed deploying PHP web shells following compromise.
CVE-2019-1068 – Microsoft SQL Server
A remote code execution vulnerability that can allow arbitrary code to execute with the privileges of the SQL Server Database Engine service account.
CVE-2022-0995 – Linux Kernel
An out-of-bounds memory write vulnerability capable of enabling local privilege escalation or denial of service.
CVE-2015-5287 – Red Hat ABRT
A privilege-escalation flaw involving predictable filenames and symbolic links.
CVE-2015-3246 – Red Hat libuser
A race condition that can potentially allow a local attacker to manipulate /etc/passwd, leading to privilege escalation or denial of service.
CVE-2021-23758 – Ajax.NET Professional
An insecure deserialisation vulnerability capable of enabling remote code execution in affected ASP.NET applications.
For defenders, the range of technologies involved means identifying vulnerable assets may require coordination across network, Windows, Linux and application teams.
Of the six vulnerabilities, the activity surrounding CVE-2026-8452 provides the clearest evidence of ongoing post-exploitation behaviour.
Threat intelligence reporting identified 36 exploitation attempts from 12 unique IP addresses over approximately 12 days. Attack infrastructure was distributed across several regions, although the location of those IP addresses should not be interpreted as evidence of attacker nationality or attribution.
More importantly, attackers have moved beyond simply testing whether NetScaler appliances are vulnerable.
Following successful exploitation, PHP web shells named x.php and z.php have reportedly been written to compromised systems. Attackers were then observed executing basic discovery commands such as id and echo.
The presence of a web shell should be treated as evidence of a potential compromise rather than simply an unsuccessful vulnerability scan.
Four of the other newly listed vulnerabilities have been associated with UAT-10147, a Chinese cybercrime group targeting Windows and Linux web servers across sectors including education, media, technology and gaming.
What stands out is the age of some of the weaknesses being exploited. Two were originally disclosed in 2015, yet remain useful to attackers more than a decade later.
Legacy servers, forgotten internet-facing applications and infrastructure sitting outside normal patch-management processes can remain vulnerable long after security updates become available. Attackers do not necessarily need a new zero-day if an old vulnerability still provides the access they need.
Internet-facing infrastructure continues to provide an attractive route into enterprise networks.
Edge appliances, public web servers and externally accessible applications can give attackers an initial foothold without requiring phishing or malware delivery to an employee. Once inside, vulnerabilities such as the Linux and Red Hat privilege-escalation flaws may then provide opportunities to increase access.
The observed activity demonstrates a familiar attack path:
Internet-facing vulnerability → Initial access → Command execution/web shell → Discovery → Privilege escalation → Further compromise The use of ordinary system commands during these attacks also makes behavioural monitoring particularly important. Commands such as id, whoami or hostname are legitimate utilities and cannot simply be blocked based on their presence alone.
Organisations should first establish whether any of the six affected technologies are present within their environment, prioritising internet-facing NetScaler systems.
For NetScaler infrastructure, SOC teams should retrospectively search for unexpected PHP files, particularly x.php and z.php, alongside recently created or modified web content. Web-server processes spawning command shells should also trigger investigation.
Other useful behaviours to monitor include:
Where exploitation indicators appear alongside post-compromise behaviour, the affected system should be investigated as a potential intrusion rather than treated solely as a vulnerability-management issue.
Affected systems should be patched or otherwise remediated as a priority, with CVE-2026-8452 on exposed NetScaler infrastructure receiving immediate attention.
Organisations should also identify legacy Linux and Red Hat systems that may not be visible within standard patch-management platforms, review externally accessible SQL Server instances and establish whether any public-facing applications continue to use AjaxPro.
Remediation should then be verified rather than relying exclusively on vulnerability scanner status. More broadly, the CISA KEV catalogue should be incorporated into vulnerability-management processes so that actively exploited vulnerabilities automatically receive greater priority, particularly when they affect internet-facing assets.
The addition of these six vulnerabilities to CISA’s KEV catalogue reinforces the continued threat posed by known weaknesses in exposed enterprise infrastructure.
CVE-2026-8452 presents the clearest immediate concern. Attackers are not merely scanning for vulnerable Citrix NetScaler appliances; observed activity includes web-shell deployment and subsequent host reconnaissance, indicating successful compromise in at least some cases.
The inclusion of much older vulnerabilities is equally instructive. A vulnerability’s age does not make it harmless if the affected system remains accessible and unpatched.
For defenders, KEV exposure should therefore be considered more than a vulnerability-management finding. Where an actively exploited vulnerability is discovered on an exposed asset, it should also act as a trigger for retrospective threat hunting to establish whether compromise has already occurred.
Patching vulnerabilities is essential, but where exploitation is already taking place, remediation alone cannot determine whether an attacker gained access beforehand.
NormCyber’s Managed Detection and Response (MDR) service provides continuous monitoring across endpoints, servers, identities and network activity, helping organisations identify the behaviours that follow successful exploitation.
Our SOC analysts investigate suspicious process execution, web-shell activity, privilege escalation, unusual outbound connections and reconnaissance behaviour across the environment. By correlating vulnerability exposure with security telemetry, NormCyber MDR can help organisations move beyond simply identifying vulnerable systems to understanding whether those vulnerabilities are actively being targeted or have already been exploited. With 24/7 expert monitoring and response, organisations can detect and contain attacker activity earlier, reducing the opportunity for an initial vulnerability exploit to develop into wider network compromise.
Primary: CISA – CISA Adds Six Known Exploited Vulnerabilities to Catalog
Secondary: The Hacker News – CISA Adds Six Exploited Flaws to KEV Catalog