Cybersecurity Aug 28, 2026Add to bookmarks

The CISA has just added six new entries to its KEV (Known Exploited Vulnerabilities) catalog. These include vulnerabilities in NetScaler (Citrix), the Linux kernel, and Microsoft SQL Server—all actively exploited in real-world conditions.
The CISA (Cybersecurity and Infrastructure Security Agency) has updated its KEV (Known Exploited Vulnerabilities) catalog with six new entries. The KEV is the U.S. government’s official list of vulnerabilities for which real-world exploitation has been documented—it’s the list that triggers patching obligations for federal agencies and serves as the highest-priority signal for the entire sector.
According to The Hacker News, the three product families affected in this update are NetScaler (Citrix), the Linux kernel, and Microsoft SQL Server.
In our ongoing tracking of critical U.S. infrastructure since early 2026, the KEV is the most reliable indicator of what is actually being exploited—as opposed to theoretical CVEs. Each KEV addition represents documented incidents, often against sensitive targets.
Since launching our [cisa-infra-critique-2026] thread, we’ve observed a particularly sustained pace of KEV additions, with a preponderance of flaws targeting remote access (VPN, RDP, load balancers) and the hypervisor/virtualization layer.
CISA has been regularly adding new entries to the KEV in 2026, with a preponderance of flaws targeting remote access equipment (VPN, load balancers) and hypervisors. NetScaler (Citrix) remains among the most frequently targeted products.
Immediate actions:
The NVD (National Vulnerability Database) catalogs all known CVEs, whether exploitable or not. The KEV contains only CVEs for which real-world exploitation has been confirmed. An NVD patch can wait; a KEV patch cannot.
Article produced by artificial intelligence, reviewed under human editorial control.
CISA et la résilience des infrastructures critiques américaines en 2026