INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Six Exploited Flaws in Microsoft, Linux Products
| 2026-08-27 10:45 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day, urging government agencies and critical infrastructure organizations to patch them quickly. The vulnerabilities include memory overflow vulnerabilities in Microsoft products such as NetScaler ADC and NetScaler Gateway, remote code execution vulnerabilities in older versions of the same software, and several-year-old flaws that must be patched by September 9. CISA warned of these exploits on August 26, with six new KEV listings added to its catalog over the next two days, including a memory overflow vulnerability in Citrix products. The agency urged government agencies to apply patches for both vulnerabilities by August 29 and reminded them that Microsoft products must be patched by September 9 due to several-year-old flaws.
Technical Mitigations AI-generated
* Implement a secure patching strategy for all affected systems, including regular updates and patches from vendors to ensure timely resolution of the vulnerabilities.
* Conduct thorough risk assessments and vulnerability scanning to identify potential entry points for attackers exploiting the identified vulnerabilities.
* Educate users on how to prevent exploitation of these vulnerabilities by following best practices such as keeping software up-to-date, using strong passwords, and being cautious when opening emails or attachments from unknown sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
aj•••••.net
x•••••.php
z•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2015-3246CVE-2015-3246
CVE-2019-1068CVE-2019-1068
CVE-2026-8452CVE-2026-8452
CVE-2015-5287CVE-2015-5287
CVE-2022-0995CVE-2022-0995
CVE-2021-23758CVE-2021-23758
Target & Sectors
ASEAN
ASEAN
NORTH_AMERICA
NORTH_AMERICA
DACH
DACH
BENELUX
BENELUX
governmentgovernment
mediamedia
educationeducation
technologytechnology
Incident Timeline
August 26
Threat actors used a six-year-old flaw in Microsoft products to target Citrix systems on August 26.
Click on any entity below to view its context and source!
source_region
United States
The US Cybersecurity and Infrastructure Security Agency (CISA)
added six new flaws
to its
Known Exploited Vulnerabilities (KEV) catalog
in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
Other vulnerabilities added to the CISA KEV catalog on August 26, all several-year-old flaws, must be patched by September 9, the US agency said.
industry
Government
The US Cybersecurity and Infrastructure Security Agency (CISA)
added six new flaws
to its
Known Exploited Vulnerabilities (KEV) catalog
in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
attribution
Known Exploited
The US Cybersecurity and Infrastructure Security Agency (CISA)
added six new flaws
to its
Known Exploited Vulnerabilities (KEV) catalog
in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
tactic
T1588.006 - Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA)
added six new flaws
to its
Known Exploited Vulnerabilities (KEV) catalog
in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
attribution
KEV
The US Cybersecurity and Infrastructure Security Agency (CISA)
added six new flaws
to its
Known Exploited Vulnerabilities (KEV) catalog
in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
Aug 27, 2026
Threat actors used a known vulnerability in Citrix products to gain unauthorized access.
2026/08/27
Threat actors used a race condition vulnerability in Red Hat libuser to target Citrix NetScaler ADC and NetScaler Gateway.
Click on any entity below to view its context and source!
infrastructure
Linux
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs.
The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
NET professional deserialization of untrusted data vulnerability (CVSS rating: 8.1)
CVE-2022-0995 Linux kernel out-of-bounds write vulnerability (CVSS rating: 7.8)
Image credits: Pavel Kapysh / JHVEPhoto / Shutterstock.com
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products.
CVE-2022-0995
- An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
organisation
Red Hat
Red Hat Libuser race condition vulnerability (CVSS rating: 5.1)
CVE-2015-5287: Red Hat automatic bug reporting tool privilege escalation vulnerability (CVSS rating: 7.8)
CVE-2021-23758: Ajax.
CVE-2015-3246
- A race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
victims
5.1 Libuser condition vulnerability
Red Hat Libuser race condition vulnerability (CVSS rating: 5.1)
CVE-2015-5287: Red Hat automatic bug reporting tool privilege escalation vulnerability (CVSS rating: 7.8)
CVE-2021-23758: Ajax.
organisation
CVE-2015
CVE-2015-5287
- A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name.
CVE-2015-3246
Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758
Ajax.
They include:
CVE-2015-3246:
organisation
Red Hat Automatic Bug Reporting
CVE-2015-5287
- A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name.
organisation
Microsoft
CVE-2015-3246
Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758
Ajax.
The vulnerabilities are listed below -
CVE-2019-1068
- A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
organisation
CVE-2022-0995
The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
organisation
KEV
The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
Despite a patch having been available for seven years, the KEV addition shows threat actors are still actively exploiting the flaw in unpatched systems.
Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
infrastructure
Windows
The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
organisation
CVE-2021-23758
CVE-2021-23758
- A deserialization of untrusted data vulnerability in Ajax.
organisation
Ajax
CVE-2021-23758
- A deserialization of untrusted data vulnerability in Ajax.
organisation
CVE-2022-0995 Linux
NET professional deserialization of untrusted data vulnerability (CVSS rating: 8.1)
CVE-2022-0995 Linux kernel out-of-bounds write vulnerability (CVSS rating: 7.8)
Image credits: Pavel Kapysh / JHVEPhoto / Shutterstock.com
organisation
Shutterstock.com
NET professional deserialization of untrusted data vulnerability (CVSS rating: 8.1)
CVE-2022-0995 Linux kernel out-of-bounds write vulnerability (CVSS rating: 7.8)
Image credits: Pavel Kapysh / JHVEPhoto / Shutterstock.com
organisation
CVE-2022-0995
- An
CVE-2022-0995
- An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
organisation
NetScaler ADC
The first, tracked as CVE-2026-8452, is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
organisation
NetScaler Gateway
The first, tracked as CVE-2026-8452, is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
CVE-2026-8452
- An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
organisation
CVE-2026
CVE-2026-8452
- An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
organisation
Citrix NetScaler ADC
CVE-2026-8452
- An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.
organisation
KEVIntel
The development comes as both
Defused Cyber
and
Previdian
(formerly KEVIntel) warned of active exploitation efforts aimed at
CVE-2026-8452
.
infrastructure
14.1-72
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1-63
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
14.1-FIPS
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1-FIPS
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1-NDcPP
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1.37
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
8.8
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
organisation
NetScaler
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
organisation
Microsoft SQL
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
14.1 FIPS
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
infrastructure
13.1 FIPS
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
organisation
the SQL
The vulnerabilities are listed below -
CVE-2019-1068
- A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
It can allow an attacker to execute code in the context of the SQL Server Database Engine service account.
organisation
NET Professional
NET Professional (AjaxPro) that could allow for remote code execution via arbitrary .NET classes.
organisation
CVSS
It was reported by Citrix at the end of June and attributed a severity rating (CVSS) of 8.8.
organisation
DoS
Exploiting the flaw can lead to unpredictable or erroneous behavior and denial of service (DoS) if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
organisation
ICA
Exploiting the flaw can lead to unpredictable or erroneous behavior and denial of service (DoS) if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
organisation
AAA
Exploiting the flaw can lead to unpredictable or erroneous behavior and denial of service (DoS) if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
organisation
SQL
Exploiting this vulnerability involves submitting a specially crafted query to an affected SQL server.
organisation
IP
Telemetry data
shows
that 36 exploitation attempts have been detected over the past 12 days from 12 unique attacker IP addresses from Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam.
financial
04 BOD
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of
KEV Catalog vulnerabilities
.
organisation
CVE
According to the agency's analysis of CVE records from 2024 and 2025, injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025.
organisation
Aware
Aware of an exploited vulnerability not currently listed in the KEV Catalog?
August 29
Microsoft, Linux and Red Hat software were found to have six newly discovered vulnerabilities that could be exploited by threat actors.
Click on any entity below to view its context and source!
industry
Government
CISA urged government agencies to apply patches for both vulnerabilities by August 29.
August 29, 2026
Threat actors used a vulnerability in Microsoft products to target Citrix systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8452
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
vulnerability
CVE-2019-1068
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
attribution
Federal Civilian Executive Branch
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
attribution
FCEB
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
September 9
Microsoft, Linux and Red Hat operating systems were found to have six previously unknown vulnerabilities.
Click on any entity below to view its context and source!
target_region
United States
Other vulnerabilities added to the CISA KEV catalog on August 26, all several-year-old flaws, must be patched by September 9, the US agency said.
September 9, 2026
Threat actors used a vulnerability in Citrix products to target Microsoft and Linux systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8452
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
vulnerability
CVE-2019-1068
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
attribution
Federal Civilian Executive Branch
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
attribution
FCEB
CISA is urging Federal Civilian Executive Branch (FCEB) agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the rest by September 9, 2026.
Tactical Metrics
Metrics
victims
5
Libuser Condition Vulnerability
Click for context!
Red Hat Libuser race condition vulnerability (CVSS rating: 5.1)
CVE-2015-5287: Red Hat automatic bug reporting tool privilege escalation vulnerability (CVSS rating: 7.8)
CVE-2021-23758: Ajax.
Metrics
infrastructure
Linux
Affected Product
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products.
NET professional deserialization of untrusted data vulnerability (CVSS rating: 8.1)
CVE-2022-0995 Linux kernel out-of-bounds write vulnerability (CVSS rating: 7.8)
Image credits: Pavel Kapysh / JHVEPhoto / Shutterstock.com
…CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs.
CVE-2022-0995
- An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Metrics
infrastructure
14.1-72
Software Version
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FI…
Metrics
infrastructure
13.1-63
Software Version
…updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetS…
Metrics
infrastructure
13.1
Software Version
…updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetS…
Metrics
infrastructure
14.1-FIPS
Software Version
…-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later…
Metrics
infrastructure
13.1-FIPS
Software Version
…and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a re…
Metrics
infrastructure
13.1-NDcPP
Software Version
…eases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code exec…
Metrics
infrastructure
13.1.37
Software Version
….1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE)…
Metrics
infrastructure
8.8
Software Version
…DC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
The second, CVE-2019-1068, is a remote code execution (RCE) vulnerability in Microsoft SQL server discovered in 2019, with the same severity rating of 8.8.
Metrics
infrastructure
14
Fips
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIP…
Metrics
infrastructure
13
Fips
Citrix has provided a patch in the following updates:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIP…
Metrics
infrastructure
Windows
Affected Product
…CVE-2021-23758 to the KEV catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as
UAT-10147
that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
Metrics
financial
4
Bod
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of
KEV Catalog vulnerabilities
.
Intelligence Sources
The Hacker News
2026-08-27
CISA
2026-08-26
Infosecurity-Magazine
2026-08-27
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-28T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
30x
organisation
Identified Entity
Red Hat
entity
14x
timeline
Temporal Reference
August 26
date
13x
attribution
Attributing Entity
The US Cybersecurity and Infrastructure Security Agency
authority
10x
target region
Target Country
United States
country
8x
infrastructure
Software Version
14.1-72
version
6x
vulnerability
Exploited CVE
CVE-2015-5287
cve
4x
industry
Targeted Sector
Government
sector
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
source region
Origin Country
United States
country
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
2x
infrastructure
Affected Product
Linux
software
2x
infrastructure
Fips
14
fips
2x
general metric
A
5,287
a
Contextual Telemetry
Context Block
12 METRICS
victims
Libuser Condition Vulnerability
5
libuser condition vulnerability
general metric
Reporting Escalation Vulnerability
8
reporting escalation vulnerability
general metric
Cve-2026
8,452
cve-2026
general metric
Netscaler Gateway
13
netscaler gateway
general metric
Cvss Rating
8
cvss rating
general metric
Linux
995
linux
general metric
August
26
august
general metric
Exploitation Attempts
36
exploitation attempts
general metric
Unique Attacker
12
unique attacker
general metric
Aug
27
aug
general metric
Escalation Vulnerability
1,068
escalation vulnerability
financial
Bod
4
bod
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.