← Knowledge Center
Advisory CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995, CVE-2026-8452

CISA Adds Six Actively Exploited Flaws to KEV, Including Citrix NetScaler Bug

CISA has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The set includes several privilege escalation and memory-safety issues that are directly relevant to identity and access defense: CVE-2015-3246 (Red Hat Libuser race condition) and CVE-2015-5287 (ABRT privilege escalation) can allow local attackers to gain elevated rights, while CVE-2022-0995 (Linux kernel out-of-bounds write) offers another path to escalation. CVE-2019-1068 (Microsoft SQL Server RCE), CVE-2021-23758 (Ajax.NET deserialization), and CVE-2026-8452 (Citrix NetScaler ADC/Gateway memory buffer flaw) round out the list.

The Citrix NetScaler entry is particularly notable given that gateway appliances are common footholds for credential theft, session hijacking, and pivoting into internal directories. Privilege escalation flaws matter for AD environments because attackers who compromise a single host frequently chain local escalation to move toward domain-level control.

What to take away: Under BOD 26-04, federal agencies must prioritize rapid remediation, but any organization should treat KEV-listed flaws—especially the NetScaler gateway and local escalation bugs—as urgent patching targets to limit paths toward identity compromise.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.