INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Red Hat Linux Kernel Exploit Vulnerability

| 2026-08-28 09:07 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The situation is critical as a series of vulnerabilities have been identified in various software products, including Microsoft SQL Server and Red Hat Automatic Bug Reporting Tool. These vulnerabilities can be exploited to gain unauthorized access, execute code, or escalate privileges, posing significant threats to organizations and individuals. The most recent incidents include the automatic bug reporting tool privilege escalation vulnerability CVE-2019-1068 and the Linux Kernel Out-of-Bounds Write Vulnerability CVE-2022-0995. Affected products range from Microsoft SQL Server to Citrix NetScaler ADC and NetScaler Gateway, highlighting a broader scope of vulnerabilities that require immediate attention. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing the need for swift action by organizations to patch these weaknesses before they can be exploited.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent privilege escalation vulnerabilities, such as those found in Red Hat Automatic Bug Reporting Tool (CVE-2019-1068) and Microsoft SQL Server Remote Code Execution Vulnerability (CVE-2021-23758). * Regularly update and patch operating systems, applications, and firmware to ensure that known vulnerabilities are addressed before they can be exploited. * Configure network devices with proper restrictions on memory buffers and use of privileged access to prevent improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8452). * Monitor systems for signs of exploitation and take prompt action if any vulnerabilities are detected, such as patching affected software and implementing security controls to prevent unauthorized access. * Educate users on how to properly use and configure network devices, including the importance of following best practices for secure coding and input validation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

aj•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8452CVE-2026-8452 CVE-2026-3055CVE-2026-3055 CVE-2026-19490CVE-2026-19490 CVE-2015-5287CVE-2015-5287 CVE-2026-4368CVE-2026-4368 CVE-2019-1068CVE-2019-1068 CVE-2015-3246CVE-2015-3246 CVE-2026-19489CVE-2026-19489 CVE-2021-23758CVE-2021-23758 CVE-2022-0995CVE-2022-0995
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎November 2021
Threat actors used a known exploit of the Citrix NetScaler vulnerability to target affected systems.
tactic Ransomware
general_metric 23 Citrix vulnerabilities
‎March 23
Threat actors used Citrix NetScaler Professional to target U.S. CISA on March 23, just days before abusing two other vulnerabilities, CVE-2026-3055 and CVE-2026-4368.
vulnerability CVE-2026-3055
vulnerability CVE-2026-4368
‎March 30
Threat actors used a known exploited vulnerability in Citrix NetScaler to target U.S. federal agencies on March 30.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVE-2026-3055
attribution CISA
‎2026/08/28
Microsoft SQL Server Remote Code Execution Vulnerability.
organisation Microsoft
organisation Red Hat Automatic Bug Reporting
organisation the SQL
organisation CVE-2021-23758
organisation KEV
organisation Ajax
organisation NetScaler
organisation DoS
infrastructure Linux
organisation NET Professional
organisation Microsoft SQL
organisation Citrix NetScaler
organisation Known Exploited
organisation CVE-2022-0995
organisation NetScaler ADC
organisation CVE-2026-8452
organisation Citrix NetScaler ADC
organisation NetScaler Gateway
organisation AAA (Authentication, Authorization
organisation Auditing
organisation CVE-2026
organisation lsn group.*sipalg
organisation SIP ALG
organisation NAT
organisation AAA
organisation ICA
organisation Gateway
organisation The ShadowServer Foundation
organisation The Blue Report 2026
infrastructure 14.1-73
infrastructure 13.1-63
infrastructure 13.1-37
organisation NetScaler ADC FIPS
infrastructure 14.1 FIPS
infrastructure 73.32 FIPS
organisation Auth
organisation Secure Private Access Hybrid
‎August 29, 2026
The U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog due to the deadlines set for federal agencies to fix CVE-2019-1068 and CVE-2026-8452 by August 29, 2026.
vulnerability CVE-2019-1068
vulnerability CVE-2026-8452
attribution CVE-2026
‎August 29
Citrix NetScaler appliances were ordered to be secured by August 29 due to the addition of CVE-2026-8452 flaw in CISA's Known Exploited Vulnerabilities catalog.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVE-2026-8452
attribution CVE-2026
attribution FCEB
attribution Federal Civilian Executive Branch
general_metric 26 Binding Operational Directive
‎September 9, 2026
The U.S. CISA ordered federal agencies to fix the Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler vulnerabilities by August 29, 2026.
vulnerability CVE-2019-1068
vulnerability CVE-2026-8452
attribution CVE-2026
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎14.1-73
Software Version
Metrics
infrastructure
‎13.1-63
Software Version
Metrics
infrastructure
‎13.1-37
Software Version
Metrics
infrastructure
14
Fips
Metrics
infrastructure
73
Fips