<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🟠 High: CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs]]></title><description><![CDATA[<p dir="auto">The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with six newly confirmed flaws, citing verified evidence of active exploitation in the wild. Among the additions is a high-severity vulnerability affecting <strong>Citrix NetScaler ADC</strong> and <strong>NetScaler Gateway</strong>, which has been flagged as an active attack vector.</p>
<p dir="auto">The newly added entries include a remote code execution flaw tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1068" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2019-1068</a></strong>, which impacts Microsoft Windows systems. This vulnerability is part of a broader batch that spans multiple vendors and platforms, including Linux-based products and Microsoft SQL Server.</p>
<ul>
<li><strong>Citrix NetScaler ADC and NetScaler Gateway</strong> — high-severity flaw with confirmed exploitation.</li>
<li><strong>Microsoft SQL Server</strong> — vulnerability included in the KEV update.</li>
<li><strong>Linux kernel</strong> — security bug added due to observed malicious activity.</li>
<li>Four additional vulnerabilities were also listed, though specific identifiers for all entries were not fully detailed in the advisory.</li>
</ul>
<p dir="auto">CISA's KEV catalog serves as a critical resource for federal agencies and private organizations, mandating remediation within established deadlines under Binding Operational Directive (BOD) 22-01. While the exact patch timelines vary by severity, all listed flaws require immediate attention to mitigate risk.</p>
<p dir="auto">Organizations using affected products are strongly urged to review their exposure, apply vendor-provided updates, and monitor for indicators of compromise tied to these exploits.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Does your organization track the KEV catalog closely, and how are you prioritizing the NetScaler and SQL Server patches given the active exploitation evidence?</p>
]]></description><link>https://xploitlk.com/topic/160/high-cisa-adds-six-exploited-flaws-to-kev-including-netscaler-linux-and-sql-server-bugs</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:17 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/160.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 31 Aug 2026 00:30:29 GMT</pubDate><ttl>60</ttl></channel></rss>