CISA lists six exploited bugs in Microsoft, Linux, Citrix

The US Cybersecurity and Infrastructure Security Agency (CISA) has added six actively exploited software vulnerabilities affecting Microsoft, Linux, Red Hat and Citrix products to its Known Exploited Vulnerabilities (KEV) catalog, ordering US federal civilian agencies to remediate them by September 9 following evidence of in-the-wild attacks.[1][4][8][14]

Among the newly listed flaws are two Microsoft vulnerabilities, including CVE-2019-1068, a remote code execution bug in Microsoft SQL Server carrying a CVSS v3 base score of 8.8 that was originally disclosed in 2019 but is now confirmed to be under active exploitation.[1][4][8] Successful exploitation of this vulnerability can allow an attacker to execute arbitrary code in the context of the SQL Server service account, potentially leading to full compromise of databases and associated applications if instances remain unpatched.[1][8] CISA’s decision to move the bug into the KEV catalog underscores that threat actors are still finding unmitigated deployments years after vendor fixes were made available.[1][4][8]

CISA also highlighted two long-standing weaknesses in Red Hat software: CVE-2015-3246, a race condition in the libuser library rated 5.1 on the CVSS scale, and CVE-2015-5287, a privilege escalation issue in Red Hat’s Automatic Bug Reporting Tool (ABRT) with a CVSS score of 7.8.[1][4][8] Both flaws can be abused by local users to escalate privileges on affected Linux systems, turning a limited foothold into root-level control if the underlying distributions have not been updated.[1][8] Their inclusion in the KEV list more than a decade after publication signals that legacy and poorly maintained Linux servers remain an attractive target in enterprise and hosting environments.[1][4][8]

The catalog update further names CVE-2021-23758, a deserialization of untrusted data vulnerability in Ajax.NET Professional with a CVSS v3 score of 8.1 that can enable remote code execution in vulnerable ASP.NET applications, and CVE-2022-0995, an out-of-bounds write flaw in the Linux kernel rated 7.8 that attackers can leverage to escalate privileges once they gain local access.[1][4][8] Exploiting the Ajax.NET bug allows adversaries to run arbitrary code on affected web servers, making it a high-value target for initial access and web shell deployment, while the Linux kernel issue offers a reliable path to root privileges in multi-tenant and cloud environments where unprivileged accounts are common.[1][8] Both vulnerabilities have been public for several years with patches or mitigations available, yet their appearance in KEV confirms they feature in current intrusion campaigns rather than purely in proof-of-concept exploit code.[1][4][8]

CISA’s notice and accompanying catalog entries indicate that a Citrix vulnerability is also among the six additions, though public summaries reviewed so far do not detail the specific CVE identifier or affected product, beyond confirming that exploitation has been observed.[1][4][8][14] Federal agencies subject to Binding Operational Directive 22-01 must now identify any affected Microsoft SQL Server, Red Hat-based Linux distributions, Ajax.NET Professional deployments, Linux kernels and relevant Citrix appliances in their environments, and apply vendor fixes or mitigations by the September 9 deadline or formally document compensating controls.[1][2][4][8] Security teams in the private sector are strongly urged to treat the KEV catalog as a de facto patch priority list, with particular focus on externally exposed SQL Server instances and web applications, Linux servers that may have missed older package updates, and Citrix infrastructure frequently targeted in past ransomware and espionage operations.[1][2][8][11]

Because all KEV entries are backed by evidence of real-world exploitation, organizations should assume that opportunistic and targeted attackers are actively scanning for these weaknesses and incorporate KEV-driven checks into vulnerability management, attack surface monitoring and threat hunting workflows.[1][2][4] Beyond applying vendor patches, defenders should look for signs of exploitation such as anomalous SQL Server activity, unexpected privilege escalation on Linux hosts, suspicious deserialization behavior in .NET applications and unusual traffic through Citrix gateways, using the KEV catalog as a compass for detection engineering and incident response planning.[1][2][4][8]

References

  1. Known Exploited Vulnerabilities Catalog | CISA
  2. The KEV Catalog
  3. Known Exploited Vulnerabilities Catalog | CISA
  4. CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix
  5. CISA KEV Updates August 2026 – HackerStorm.com
  6. SECURITY NEWS (2026/08) – 電気通信大学 情報基盤センター

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply