CISA Adds Microsoft SQL Server, Citrix NetScaler, Linux Kernel and More to Exploited Catalog

Let me ask you something: if you knew a back door was being used to enter your business, would you leave it unlocked until next week?

Of course not. But that is essentially the risk created when a vulnerability enters CISA’s Known Exploited Vulnerabilities (KEV) catalog. On August 26, 2026, CISA added six vulnerabilities to catalog version 2026.08.26, including flaws affecting Microsoft SQL Server, Citrix NetScaler, the Linux kernel, and older software components.

The catalog is CISA’s authoritative list of vulnerabilities known to be exploited in the wild. That does not mean every small business is being targeted by each vulnerability today. It does mean you should treat these issues as urgent if the affected products exist anywhere in your environment.

Category: CISA Advisories

The six CISA KEV vulnerabilities added on August 26

Here is the short version:

CVE Affected product Potential impact CISA due date
CVE-2019-1068 Microsoft SQL Server Remote code execution August 29, 2026
CVE-2026-8452 Citrix NetScaler ADC and Gateway Denial of service August 29, 2026
CVE-2022-0995 Linux kernel Privilege escalation or denial of service September 9, 2026
CVE-2021-23758 Ajax.NET Professional Remote code execution September 9, 2026
CVE-2015-3246 Red Hat Libuser Privilege escalation or denial of service September 9, 2026
CVE-2015-5287 Red Hat ABRT Privilege escalation September 9, 2026

None of the six vulnerabilities is marked by CISA as being used in known ransomware campaigns. That is helpful context, but it is not a reason to delay action.

Known exploitation is already enough to move these vulnerabilities near the top of your patching list.

1. CVE-2019-1068: Microsoft SQL Server remote code execution

Microsoft SQL Server stores some of your most valuable business information: customer records, financial data, employee information, application data, and operational records.

CVE-2019-1068 is a remote code execution vulnerability. An attacker may be able to execute code in the context of the SQL Server Database Engine service account.

In plain English, the attacker could potentially make the database server perform unauthorized actions. The final impact depends on how the service account is configured, what permissions it has, and what other systems it can reach.

Protected server and business data represented by a subtle security shield

Here is what you should do:

  • Identify every Microsoft SQL Server instance in your environment.
  • Confirm the exact SQL Server version and update level.
  • Apply the appropriate Microsoft security update.
  • Review the permissions assigned to the SQL Server service account.
  • Restrict SQL Server access to only the systems and users that need it.
  • Review database logs for unusual commands, account activity, or configuration changes.

CISA’s action deadline for this entry is August 29, 2026. You can review the Microsoft security guidance for CVE-2019-1068 and the related NVD vulnerability record.

2. CVE-2026-8452: Citrix NetScaler memory buffer vulnerability

Do you use Citrix NetScaler ADC or NetScaler Gateway for remote access, SSL VPN, application delivery, or authentication?

If so, pay close attention to CVE-2026-8452.

This vulnerability involves improper restriction of operations within the bounds of a memory buffer, classified as CWE-119. It could cause unpredictable behavior or a denial-of-service condition when the appliance is configured as a Gateway or AAA virtual server.

And here is why this matters: your NetScaler appliance may be the front door employees use to reach business systems from outside the office. If that front door crashes, remote access and critical applications may become unavailable.

Start by:

  • Confirming whether your business operates a customer-managed NetScaler appliance.
  • Checking the appliance version against Citrix’s current security guidance.
  • Applying the vendor-provided update or mitigation.
  • Reviewing gateway, VPN, AAA, and authentication configurations.
  • Monitoring for unexpected crashes, reloads, service interruptions, or configuration changes.
  • Limiting administrative access while remediation is in progress.

CISA’s due date is August 29, 2026. Review the Citrix security bulletin and the NVD details for CVE-2026-8452.

3. CVE-2022-0995: Linux kernel out-of-bounds write

Linux servers often run quietly in the background. They may host websites, applications, databases, file services, cloud workloads, or security tools.

That quiet role can make them easy to overlook.

CVE-2022-0995 is an out-of-bounds memory write vulnerability in the Linux kernel. A local user could potentially use it to gain privileged access or cause a denial-of-service condition.

A privileged account is much more than just another login. It can change system settings, access protected files, install software, or create new accounts.

Your response should include:

  • Inventorying Linux servers, virtual machines, cloud workloads, and appliances.
  • Checking the kernel version and distribution-specific advisories.
  • Applying the appropriate update from Red Hat, Ubuntu, Debian, or your Linux vendor.
  • Rebooting systems when required so the updated kernel is actually active.
  • Reviewing local users, SSH access, and recently changed privileges.
  • Monitoring system logs for crashes, unexpected reboots, or suspicious account activity.

CISA gives organizations until September 9, 2026, for this entry. See the CVE-2022-0995 record from NIST.

4. CVE-2021-23758: Ajax.NET Professional deserialization flaw

CVE-2021-23758 affects Ajax.NET Professional, also known as AjaxPro.

The vulnerability involves deserialization of untrusted data. That technical phrase means the software may accept specially crafted data and turn it into executable objects without safely validating what it received.

The result could be remote code execution through arbitrary .NET classes.

Here’s the bigger concern: this product may be end-of-life. If your organization still depends on an old application using AjaxPro, a routine patch may not be available or sufficient.

CISA advises users to discontinue use or transition to a supported version when appropriate.

Start by asking:

  • Does any internal or customer-facing application use AjaxPro?
  • Is the package present in older .NET applications?
  • Is the application still supported by its developer?
  • Can the application be isolated while you plan a replacement?
  • Are there external-facing endpoints that accept untrusted requests?

The remediation deadline is September 9, 2026. Review the NVD record for CVE-2021-23758.

5. CVE-2015-3246: Red Hat Libuser race condition

CVE-2015-3246 affects Red Hat Libuser and involves a race condition.

A race condition happens when software handles two actions in an unsafe order. An authenticated local user could potentially exploit this issue to corrupt the /etc/passwd file, resulting in denial of service or privilege escalation.

The /etc/passwd file is a core Linux system file that helps define local user accounts. Corrupting it can disrupt logins and system operation.

This vulnerability may be especially relevant on older Red Hat systems that have not been regularly maintained.

Check for:

  • Legacy servers that are still running in production.
  • Systems with outdated Red Hat packages.
  • Local accounts that are no longer needed.
  • Shared administrative access.
  • Unsupported operating system versions.

Apply the vendor update where available, or develop a replacement plan for systems that are no longer supported. The CISA due date is September 9, 2026.

More information is available in the NVD record for CVE-2015-3246.

6. CVE-2015-5287: Red Hat ABRT symlink attack

The final entry, CVE-2015-5287, affects the Red Hat Automatic Bug Reporting Tool, commonly called ABRT.

This vulnerability can allow privilege escalation through a symlink attack involving a file with a predictable name. In simple terms, an attacker may attempt to trick the system into writing to the wrong location, potentially changing files or settings with higher privileges.

As with AjaxPro, the affected product may be end-of-life in some environments. That makes asset identification just as important as patching.

Review:

  • Whether ABRT is installed on any Red Hat systems.
  • Whether the system is still supported.
  • Whether the tool is required for business operations.
  • Whether it can be removed or disabled safely.
  • Whether an operating system upgrade or system replacement is needed.

The remediation deadline is September 9, 2026. See the NVD record for CVE-2015-5287.

What BOD 26-04 means for your business

All six entries include CISA’s guidance under BOD 26-04, which focuses on prioritizing security updates based on risk.

The recommended approach is to:

  • Apply vendor mitigations or patches.
  • Follow applicable cloud-service guidance.
  • Discontinue use of the product if effective mitigation is unavailable.
  • Evaluate whether each asset is exposed to the internet.
  • Perform additional review when exploitation may have occurred.

You do not need to wait for an incident to begin. Start with your inventory.

Now think about your own environment in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, or elsewhere in Missouri. Do you know which servers, remote-access appliances, cloud systems, and legacy applications you have? If not, patching is only part of the problem.

How Platinum Web Services can help

Platinum Web Services helps small businesses assess exposure, identify vulnerable systems, coordinate updates, and improve ongoing protection.

Our cybersecurity solutions can support vulnerability reviews, network security, cloud services, endpoint protection, and proactive monitoring. We also provide network design, laptop and desktop repairs, virus removal, data recovery, and 24/7 IT support when an urgent problem cannot wait.

For practical patching workflow ideas, review our guide on five steps to patch today’s biggest CISA vulnerabilities.

CISA’s KEV catalog is a warning system. It tells you which weaknesses deserve attention now.

If you would like help determining whether CVE-2019-1068, CVE-2026-8452, CVE-2022-0995, CVE-2021-23758, CVE-2015-3246, or CVE-2015-5287 affects your business, contact Platinum Web Services. We help businesses like yours turn urgent security alerts into a clear, manageable action plan.

Sources

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *