CISA KEV: Six new actively exploited vulnerabilities - NetScaler, Linux, and SQL Server under alert

In this saga : CISA et la résilience des infrastructures critiques américaines en 2026· Episode 2/3

Cybersecurity Aug 28, 2026Add to bookmarks

CISA KEV: Six new actively exploited vulnerabilities - NetScaler, Linux, and SQL Server under alert

The CISA has just added six new entries to its KEV (Known Exploited Vulnerabilities) catalog. These include vulnerabilities in NetScaler (Citrix), the Linux kernel, and Microsoft SQL Server—all actively exploited in real-world conditions.

What: Six confirmed vulnerabilities exploited in production

The CISA (Cybersecurity and Infrastructure Security Agency) has updated its KEV (Known Exploited Vulnerabilities) catalog with six new entries. The KEV is the U.S. government’s official list of vulnerabilities for which real-world exploitation has been documented—it’s the list that triggers patching obligations for federal agencies and serves as the highest-priority signal for the entire sector.

According to The Hacker News, the three product families affected in this update are NetScaler (Citrix), the Linux kernel, and Microsoft SQL Server.

Who is impacted

  • NetScaler (Citrix ADC / Gateway): exposed on the internet in most enterprises using Citrix for VPN and remote access. NetScaler is a recurring KEV target—ransomware groups have favored it as an entry point since 2023.
  • Linux kernel: any unpatched Linux server infrastructure is potentially affected. The exact nature of the flaws (LPE, RCE, sandbox escape) will determine patching priority based on exposure.
  • SQL Server: instances exposed or accessible from compromised network segments are at risk. A KEV-listed SQL Server flaw often ties into post-exploitation lateral movement scenarios.

Context: KEV as a barometer of active threat

In our ongoing tracking of critical U.S. infrastructure since early 2026, the KEV is the most reliable indicator of what is actually being exploited—as opposed to theoretical CVEs. Each KEV addition represents documented incidents, often against sensitive targets.

Since launching our [cisa-infra-critique-2026] thread, we’ve observed a particularly sustained pace of KEV additions, with a preponderance of flaws targeting remote access (VPN, RDP, load balancers) and the hypervisor/virtualization layer.

What to do now

KEV 2026: The cadence is accelerating

CISA has been regularly adding new entries to the KEV in 2026, with a preponderance of flaws targeting remote access equipment (VPN, load balancers) and hypervisors. NetScaler (Citrix) remains among the most frequently targeted products.

Immediate actions:

  1. NetScaler: apply Citrix security bulletins immediately. Check access logs for abnormal exploitation patterns on authentication endpoints and VPN.
  2. Linux kernel: identify the exact flaw version via the updated CISA advisory, compare against production kernels, prioritize internet-facing or multi-tenant systems.
  3. SQL Server: restrict port 1433 access to authorized network segments only, apply the corresponding Microsoft patch, audit SQL Server service accounts for prior compromise.
  4. Federal/public sector: U.S. agencies have a patching obligation within the deadlines specified by CISA for each KEV entry.
KEV vs NVD: What’s the difference?

The NVD (National Vulnerability Database) catalogs all known CVEs, whether exploitable or not. The KEV contains only CVEs for which real-world exploitation has been confirmed. An NVD patch can wait; a KEV patch cannot.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

2 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

CISA et la résilience des infrastructures critiques américaines en 2026

  1. 1SilentShield 2026 Exercises: CISA Red Team Penetrates Two Critical Infrastructures, One Without Any Detection27/08/2026
  2. 2CISA KEV: Six new actively exploited vulnerabilities - NetScaler, Linux, and SQL Server under alert28/08/2026
  3. 3Pacemakers under fire, millions of stolen records: healthcare, the new frontier of cyberattacks on critical infrastructure01/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information