Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

CISA Adds Six Critical Flaws Across Red Hat, Linux Kernel, Microsoft SQL Server, Ajax.NET Professional, and Citrix NetScaler to KEV Catalog

CISA has placed six vulnerabilities—spanning Red Hat, Linux Kernel, Microsoft SQL Server, Ajax.NET Professional, and Citrix NetScaler—into its Known Exploited Vulnerabilities catalog, flagging them as actively exploited. For SOC 2‑aligned organizations, the list creates a clear, regulator‑driven trigger to demonstrate timely remediation and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 securityaffairs.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

CISA Adds Six Critical Flaws Across Red Hat, Linux Kernel, Microsoft SQL Server, Ajax.NET Professional, and Citrix NetScaler to KEV Catalog

What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed six publicly disclosed vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog, flagging them as actively exploited and requiring federal agencies to remediate them by the dates set in Binding Operational Directive 22‑01.

Exploitability – All six CVEs have evidence of real‑world exploitation. The catalog is intended for vulnerabilities with confirmed exploit activity, making them high‑risk for any environment that runs the affected software.

Affected Products –

  • CVE‑2015‑3246 – Red Hat libuser race condition (local privilege escalation / DoS)
  • CVE‑2015‑5287 – Red Hat ABRT privilege escalation via symlink attack
  • CVE‑2019‑1068 – Microsoft SQL Server remote code execution
  • CVE‑2021‑23758 – Ajax.NET Professional deserialization RCE
  • CVE‑2022‑0995 – Linux Kernel out‑of‑bounds write (local privilege escalation / DoS)
  • CVE‑2026‑8452 – Citrix NetScaler ADC/Gateway memory‑buffer bounds error (DoS, observed exploitation)

Why It Matters for Compliance & Audit Readiness –

  • Control Mapping – SOC 2 CC6.1 (Vulnerability Management) requires documented processes for identifying, assessing, and remediating known‑exploited flaws; the KEV list gives a concrete, regulator‑driven trigger.
  • Continuous Evidence – Demonstrating timely patching against a government‑published KEV catalog provides strong audit evidence of due‑diligence and risk mitigation.
  • Enterprise Buyer Expectations – Many large customers now request proof that vendors track and remediate KEV‑listed vulnerabilities as part of their SOC 2 readiness assessments.

Recommended Actions –

  • Inventory all assets running the six affected components.
  • Map each CVE to the relevant SOC 2 control (CC6.1) and assign remediation owners.
  • Apply vendor patches or mitigations immediately; if patching is not feasible, implement compensating controls (network segmentation, application‑level firewalls).
  • Capture remediation tickets, patch logs, and configuration snapshots as continuous audit evidence.
  • Update your vulnerability‑management dashboard to flag any future KEV additions automatically.

Source: Security Affairs – CISA adds Red Hat, Linux Kernel, Ajax.NET, Microsoft SQL Server, and Citrix NetScaler flaws to KEV catalog

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →