Five of the six new KEV entries date from 2015 to 2022
On 26 August 2026 CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalogue, based on evidence of active exploitation. Five of the six were published between 2015 and 2022. The sixth is a 2026 flaw in Citrix NetScaler ADC and NetScaler Gateway. CISA set a 29 August deadline for the Citrix entry and for a Microsoft SQL Server flaw, and 9 September for the remaining four. None of the six carries any known use in ransomware campaigns.
Three of the entries grant nothing but local privileges. Those are a race condition in Red Hat libuser, a symlink attack on Red Hat's automatic bug reporting tool, and an out-of-bounds memory write in the Linux kernel. The other three hit services, meaning code execution in Microsoft SQL Server, unsafe deserialisation in Ajax.NET Professional, and a memory handling flaw in Citrix NetScaler that can cause denial of service. CISA notes that Ajax.NET Professional and Red Hat's bug reporting tool may be out of support, meaning a patch may simply not exist.
What this means for you if you own the patching
Age is what deserves a pause here. Five of the six entries are between four and eleven years old, and three of them grant nothing but local privileges. Our assessment is that this says something about how an intrusion actually unfolds. An attacker gets in somewhere, then reaches for an old local flaw to move onward. That flaw was left unpatched precisely because it could not be exploited from outside, which is how it ended up at the bottom of the list.
The deadlines carry a message of their own. Two entries have to be cleared by 29 August, while the other four run to 9 September. BOD 26-04 separates vulnerabilities by risk and demands the fastest remediation where an exposed asset can be taken over entirely after exploitation. Those deadlines bind US federal agencies rather than you, but the reasoning behind them is worth borrowing. If your plan sorts by severity alone, three of these six walk straight through it.
Berigo recommends
- Handle Citrix NetScaler and Microsoft SQL Server first. Those are the two CISA gave the shortest deadline.
- Check whether you still run Ajax.NET Professional or Red Hat's automatic bug reporting tool. CISA notes that both may be out of support.
- Do not leave local privilege flaws sitting because they cannot be reached from outside. Three of the six are exactly that.
- Hold the list against your inventory of older software, not only against what is in active service today.
- Use the catalogue as a prioritisation list rather than an alerting list. Entries land there because somebody is actually exploiting them.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch