CISA adds NetScaler and SQL Server flaws to KEV
CISA added six CVEs to its KEV catalog on Aug 26, 2026, led by Citrix NetScaler CVE-2026-8452 and a 2019 SQL Server RCE, both due for federal agencies by Aug 29. CISA keeps the NetScaler bug labeled denial-of-service even as watchTowr reports RCE as root.

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, 2026, per its alert. Read the label carefully before you triage: CISA carries the headline NetScaler bug as a denial-of-service issue, not remote code execution, even though a researcher says it is worse. CISA names no threat actor for any of the six.
The two that are due first
Two of the six carry an accelerated deadline: federal civilian agencies must remediate them by August 29, tomorrow, under Binding Operational Directive 26-04.
CVE-2026-8452, in Citrix NetScaler ADC and Gateway, is the one to move on. CISA describes it as a memory-buffer flaw that could lead to denial of service, and its forensic-triage flag for the entry is set to no. That framing traces to Citrix, which in June characterized the issue as denial of service and unpredictable behavior. The dispute is that watchTowr has since demonstrated exploitation yielding remote code execution as root, and active attacks are dropping web shells on appliances. CISA has not adopted the RCE label; it kept the DoS wording. So the catalog and the field research disagree on severity, and if you run NetScaler you should plan for the worse of the two readings, not the milder one CISA printed. Fixed builds per Citrix's advisory (CTX696604) start at 14.1-72.61 and 13.1-63.18, with matching FIPS and NDcPP builds; the bug bites appliances configured as a Gateway VPN or AAA virtual server.
CVE-2019-1068, a Microsoft SQL Server remote code execution flaw, is the other Aug 29 item, and its triage flag is set to yes. Note the year: this is a 2019 authenticated RCE that runs in the SQL service-account context, not a fresh zero-day. It sat patchable for seven years and is only now being exploited in the wild.
The four nobody will headline
The remaining four are due September 9, and every one is old: CVE-2015-3246 (Red Hat libuser race condition), CVE-2015-5287 (Red Hat ABRT), CVE-2021-23758 (Ajax.NET Professional deserialization), and CVE-2022-0995 (Linux kernel watch_queue out-of-bounds write). Two are a decade old. The pattern in this batch is not novel zero-days; it is attackers monetizing long-patched Linux and application bugs on hosts nobody updated, which is why four of the six are privilege-escalation and application flaws, not perimeter appliances.
The exposure you can measure
CISA gives no victim count, but the attack surface is countable. Shadowserver telemetry, via BleepingComputer, puts roughly 22,000 NetScaler ADC appliances and about 1,800 Gateway instances reachable on the public internet, patch status unknown. That is the pool the NetScaler exploitation is drawing from.
What a defender does today
Do not wait for CISA to relabel CVE-2026-8452 as RCE before you treat it as one. Today: check your NetScaler build against the fixed versions and update anything below 14.1-72.61 or 13.1-63.18 before the Aug 29 deadline, and if you cannot patch in time, take the Gateway VPN and AAA virtual servers offline rather than leave them exposed. Then hunt for web shells and anomalous processes under the NetScaler and SQL service accounts, because the KEV listing means exploitation is already happening, not theoretical. This is a separate CVE from the NetScaler CVE-2026-19490 we covered last week, so patching one does not close the other.
For recent KEV context, see our coverage of the Gitea CVE-2026-60004 addition, TrueConf and PhantomCore, and the SharePoint, vCenter and macOS batch.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free