CISA adds six flaws to KEV catalog
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, directing federal defenders to prioritize remediation of actively exploited weaknesses in products including Citrix NetScaler ADC and NetScaler Gateway. The agency set deadlines of August 29, 2026 for CVE-2019-1068 and CVE-2026-8452, and September 9, 2026 for the remaining flaws. The update raises remediation pressure across FCEB agencies and other organizations that track KEV-listed exposure.
Related Happenings
Microsoft security patch release for CVE-2026-62832
Security Patch Release
H score5
First: 12.08.2026 09:41
Last: 12.08.2026 09:41
Sources 1
About this happening:
Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release cover...
Microsoft security patch release for CVE-2026-62832
Security Patch ReleaseAbout this happening: Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release cover...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
CISA BOD 26-04 remediation requirements
Advisory/Mitigation
H score31
First: 11.06.2026 15:46
Last: 11.06.2026 15:46
Sources 1
About this happening:
CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...
CISA BOD 26-04 remediation requirements
Advisory/MitigationAbout this happening: CISA’s Binding Operational Directive 26-04 forces FCEB agencies to speed up remediation of high-risk vulnerabilities, with some deadlines as short as 3 days and new ...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 to require federal civilian agencies to prioritize vulnerability remediation using Asset Exposure, KEV Status,...
CERT-In 12-hour KEV remediation guidance
Advisory/Mitigation
H score39
First: 26.05.2026 13:30
Last: 26.05.2026 13:30
Sources 1
About this happening:
CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
CERT-In 12-hour KEV remediation guidance
Advisory/MitigationAbout this happening: CERT-In set a 12-hour expectation for containing or remediating known exploited vulnerabilities on internet-facing and crown-jewel systems, sharply shortening response...
Timeline
-
27.08.2026 10:05 2 articles · 12h ago
CISA adds six flaws to the KEV catalog
Industry Or Public Sector UpdateCISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway and CVE-2019-1068 in Microsoft SQL Server, after evidence of active exploitation. CISA urged Federal Civilian Executive Branch agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the remaining flaws by September 9, 2026, while reporting also described web shells named x.php and z.php, discovery commands such as id and echo, and 36 exploitation attempts from 12 unique attacker IP addresses across multiple countries.
Show sources
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs — thehackernews.com — 27.08.2026 10:05
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs — thehackernews.com — 27.08.2026 10:05