Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA adds six flaws to KEV catalog

Public Sector Action
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

CISA added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, directing federal defenders to prioritize remediation of actively exploited weaknesses in products including Citrix NetScaler ADC and NetScaler Gateway. The agency set deadlines of August 29, 2026 for CVE-2019-1068 and CVE-2026-8452, and September 9, 2026 for the remaining flaws. The update raises remediation pressure across FCEB agencies and other organizations that track KEV-listed exposure.

Related Happenings

Microsoft security patch release for CVE-2026-62832

Security Patch Release
H score5 First: 12.08.2026 09:41 Last: 12.08.2026 09:41 Sources 1

About this happening: Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release cover...

SonicWall security patch release for CVE-2026-15409

Security Patch Release
H score54 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...

CISA BOD 26-04 remediation requirements

Advisory/Mitigation
H score31 First: 11.06.2026 15:46 Last: 11.06.2026 15:46 Sources 1

About this happening: CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...

CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies

Public Sector Action
H score27 First: 10.06.2026 15:00 Last: 10.06.2026 15:00 Sources 1

About this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...

CERT-In 12-hour KEV remediation guidance

Advisory/Mitigation
H score39 First: 26.05.2026 13:30 Last: 26.05.2026 13:30 Sources 1

About this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...

Timeline

  1. 27.08.2026 10:05 2 articles · 12h ago

    CISA adds six flaws to the KEV catalog

    Industry Or Public Sector Update

    CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway and CVE-2019-1068 in Microsoft SQL Server, after evidence of active exploitation. CISA urged Federal Civilian Executive Branch agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the remaining flaws by September 9, 2026, while reporting also described web shells named x.php and z.php, discovery commands such as id and echo, and 36 exploitation attempts from 12 unique attacker IP addresses across multiple countries.

    Show sources