US federal agencies have three days to deal with a Citrix NetScaler bug. Everyone else on the same list gets two weeks.
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on 26 August, all of them, the agency says, backed by evidence of active exploitation. What stands out is not the count but the clock. Two entries carry a remediation deadline of 29 August. The other four are not due until 9 September. That split is the new Binding Operational Directive 26-04 at work, which tells agencies to move fastest on publicly exposed assets where exploitation hands an attacker total control, and to defer lower-risk work rather than treat every entry the same.
The two on the short clock
The first is CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway, which CISA describes as an improper restriction of operations within the bounds of a memory buffer that could lead to denial of service. NVD rates it 8.8, high. Citrix documents it in support article CTX696604, the only vendor link CISA cites for the entry. NetScaler has been a busy target this month: we covered a separate heap overflow in the same product line two weeks ago.
The second is CVE-2019-1068, a Microsoft SQL Server remote code execution flaw that, in CISA's words, could allow an attacker to execute code in the context of the SQL Server Database Engine service account. NVD also scores it 8.8. It was patched in 2019.
Four old local flaws, and why they still matter
The rest of the batch is older and, on CISA's own descriptions, local rather than remote. Ajax.NET Professional carries CVE-2021-23758, a deserialization of untrusted data issue that could allow remote code execution via arbitrary .NET classes, rated 8.1. It is the one to watch in this group: its EPSS score sits at 0.89, meaning the model puts roughly an 89 percent probability on exploitation attempts in the next 30 days, by far the highest of the six.
Then come CVE-2015-5287 in Red Hat's Automatic Bug Reporting Tool, a privilege escalation that CISA says local users with certain permissions could reach through a symlink attack on a predictably named file, rated 7.8; CVE-2022-0995, an out-of-bounds write in the Linux kernel that could let a local user gain privileged access or crash the system, also 7.8; and CVE-2015-3246 in Red Hat libuser, a race condition allowing authenticated local users to corrupt /etc/passwd, rated 5.1. A local-only flaw is not a way in. It is what an intruder reaches for once already inside, which is why a decade-old privilege escalation still earns a place on a list built from real exploitation.
Two of the six may have no patch at all. CISA marks Ajax.NET Professional and Red Hat's Automatic Bug Reporting Tool as potentially end of life or end of service, and advises users to discontinue them or move to a supported version. It publishes no fixed-version guidance of its own for any entry in the batch, and points to vendor instructions instead.
Patch NetScaler and SQL Server by 29 August
The deadlines bind Federal Civilian Executive Branch agencies, but the exploitation evidence behind them does not stop at the US border. Work the two 29 August entries first, then the 9 September four. BOD 26-04 also asks agencies to check whether a system was already compromised before the patch went on, which is the part most private-sector readers skip. For the two end-of-life products, removal is the fix. CISA's full alert and the catalog entries are in the original advisory.
This is the second KEV addition in as many days, after a Gitea code injection flaw on 25 August. CISA publishes no CVSS scores in the catalog itself; the ratings above are NVD's.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.