CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog – Highlights Ongoing Risk Across Red Hat, Microsoft, Linux, and Citrix
What It Is — On 26 August 2026 CISA announced that six CVEs have been added to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The catalog is a curated list that federal agencies (and the broader community) use to prioritize patching.
Exploitability — All six flaws have documented exploitation by threat actors; CVSS scores range from 7.5 to 9.8, indicating high to critical severity. No public PoC is required to confirm exploitation – CISA’s evidence is based on observed attacks.
Affected Products
- CVE‑2015‑3246 – Red Hat Libuser race‑condition (privilege escalation)
- CVE‑2015‑5287 – Red Hat ABRT privilege escalation
- CVE‑2019‑1068 – Microsoft SQL Server remote code execution
- CVE‑2021‑23758 – Ajax.NET Professional deserialization of untrusted data
- CVE‑2022‑0995 – Linux Kernel out‑of‑bounds write
- CVE‑2026‑8452 – Citrix NetScaler ADC/Gateway memory‑buffer bounds error
Why It Matters for Compliance & Audit Readiness
- Control Mapping & Evidence – SOC 2’s CC6.1 (Vulnerability Management) requires documented identification, risk‑based prioritization, and remediation of security flaws; mapping each CVE to the relevant control provides a defensible audit trail.
- Continuous Monitoring – Ongoing verification that patches are applied on publicly exposed assets satisfies both BOD 26‑04 and SOC 2’s requirement for continuous risk‑based monitoring.
- Third‑Party Assurance – Demonstrating timely remediation of KEV items strengthens vendor‑risk assessments and satisfies customer‑facing SOC 2 trust‑center disclosures.
Recommended Actions
- Inventory all assets that run the listed software and tag them against the KEV list.
- Map each CVE to the corresponding SOC 2 control (e.g., CC6.1) and record remediation status in a centralized compliance repository.
- Prioritize patching based on exploitation evidence and asset criticality; apply patches or mitigations immediately.
- Validate that remediation succeeded with automated scans and retain scan reports as audit evidence.
- Integrate KEV monitoring into your continuous‑compliance platform to trigger alerts for any future KEV additions.
Source: CISA Advisory – Six Known‑Exploited Vulnerabilities Added to KEV Catalog (2026‑08‑26)