CISA Adds Citrix, SQL Server CVEs to KEV
CISA added exploited flaws in August, including Citrix NetScaler, Microsoft SQL Server and VMware vCenter, to its KEV catalog.
In August 2026, CISA added several exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, with a focus on Citrix NetScaler, Microsoft SQL Server, Windows IKE, SharePoint and VMware vCenter. The move confirms ongoing activity against widely used enterprise products and sets remediation priorities for federal agencies and exposed organizations.
CISA added several exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in August 2026, affecting widely used enterprise products such as Citrix NetScaler ADC and Gateway, Microsoft SQL Server, Microsoft Windows IKE Service Extensions, Apple macOS, Microsoft SharePoint and Broadcom VMware vCenter. Their inclusion in the KEV catalog confirms active exploitation and, in Citrix's case, triggered a particularly short federal remediation deadline.
What vulnerabilities did CISA add to the KEV in August?
CISA added CVE-2026-8452 in Citrix NetScaler, CVE-2019-1068 in Microsoft SQL Server, CVE-2026-33824 in Windows IKE, CVE-2026-65400 in macOS, CVE-2026-55040 in SharePoint, CVE-2026-59310 in VMware vCenter and CVE-2025-62593 in Ray. The list was also expanded with other exploited entries during the same period, according to summaries cited by Security Online, CyberSecureFox, FireCompass and Mallory.ai.
Security Online reported that CISA published six new exploited entries on Aug. 26, including Citrix NetScaler, Microsoft SQL Server, Red Hat and Ajax.NET. CyberSecureFox, for its part, said on Aug. 18 that four additional critical vulnerabilities were added, including Windows IKE, macOS, SharePoint and vCenter.
| CVE | Affected product | KEV status | Cited source |
|---|---|---|---|
| CVE-2026-8452 | Citrix NetScaler ADC and Gateway | Added on Aug. 26, 2026 | CISA, Security Online, OpenVPN Blog |
| CVE-2019-1068 | Microsoft SQL Server | Added to KEV | CISA, Security Online |
| CVE-2026-33824 | Microsoft Windows IKE Service Extensions | Added to KEV | CISA, CyberSecureFox |
| CVE-2026-65400 | Apple macOS, Screen Sharing | Added to KEV | CISA, CyberSecureFox |
| CVE-2026-55040 | Microsoft SharePoint | Added to KEV | CISA, CyberSecureFox |
| CVE-2026-59310 | Broadcom VMware vCenter | Added to KEV | CISA, CyberSecureFox, Tech-Insider |
| CVE-2025-62593 | Ray | Added to KEV | CISA, CyberSecureFox |
In the case of CVE-2026-8452, regulatory pressure was immediate. OpenVPN Blog said the KEV catalog set a mandatory remediation deadline for U.S. civilian federal agencies of Aug. 29, 2026, just three days after the entry was added. netVigilance also flagged it as critical and exploited in the wild, in line with Binding Operational Directive 26-04.
Why did Citrix NetScaler become the focus of the alert?
Because CVE-2026-8452 affects appliances configured with Gateway VPN or AAA virtual servers, two components that provide remote access, SSO portals and corporate authentication. BleepingComputer said the impact reaches infrastructure used by organizations for employee and third-party access, which makes the flaw a direct issue for Internet-exposed perimeters.
RedLegg said the vulnerability is being actively used for exploitation and that a confirmed proof of concept exists. It also published the affected version ranges, NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, data that helps size the potentially vulnerable footprint in enterprise and managed service environments.
Mallory.ai added operational context and said CVE-2026-8452 is being used to deploy web shells and perform reconnaissance. That same coverage placed NetScaler and SQL Server among high-value targets in recent campaigns, and recommended that U.S. private companies prioritize patching based on Internet exposure, asset criticality and business impact risk.
What does August's batch suggest?
The sequence shows CISA increasing pressure on critical enterprise infrastructure with remediation dates and priorities that vary by the level of exploitation detected. FireCompass documented that the CVEs added in August, including vCenter and Zimbra, arrived in batches with different deadlines, reinforcing a prioritization strategy for corporate platforms that concentrate sensitive services.
At the same time, HackerStorm said CVE-2026-59310 in VMware vCenter is a path traversal weakness that allows an attacker with network access to execute arbitrary code. Tech-Insider added that the flaw was seen in infrastructure across dozens of countries, with a focus on enterprise environments and cloud providers, and that three of the four critical vulnerabilities in the late-August batch received a CVSS score of 9.8.
Boerse Express also linked CISA's decision to Binding Operational Directive 26-04 and to active exploitation on the internet, consistent with the view that NetScaler holds a priority position because of its presence in corporate networks and U.S. public-sector systems.
Sources
- CVE-2025-62593: Fallo Crítico En Ray Explotado Activamentecybersecurefox.com· CyberSecureFox
- VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 Nationstech-insider.org· Tech-Insider
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (known exploited)netvigilance.com· netVigilance
- CVE-2026-73570: Zimbra Collaboration Suite Actively Exploitedsecurityarsenal.com· Security Arsenal
- Weekly CVE: 9 CISA KEV Additions: vCenter, Zimbra, and More (17–23 Aug 2026)firecompass.com· FireCompass
- Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8452)redlegg.com· RedLegg
- CVE-2026-8452: Citrix NetScaler Exploited (KEV)blog.openvpn.net· OpenVPN Blog
- CISA додає чотири критичні вразливості до KEVcybersecurefox.com· CyberSecureFox
- CISA Flags Six Exploited Vulnerabilities in KEV Catalogsecurityonline.info· Security Online
- CISA KEV Adds 4 Critical CVEs, 3 Rated CVSS 9.8 [2026]tech-insider.org· Tech-Insider
- CISA orders feds to patch Citrix NetScaler RCE flaw by August 29, 2026bleepingcomputer.com· BleepingComputer
- Metabase, un fallo crítico en el restablecimiento de contraseña da acceso de administrador sin loginpasqualepillitteri.it· Pasquale Pillitteri
- Weekly CISA KEV Updates: 24 August 2026hackerstorm.com· HackerStorm
- CISA Adds Four Critical Vulnerabilities to KEV Catalogcybersecurefox.com· CyberSecureFox
- CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Ajax.NET Flawsmallory.ai· Mallory.ai
- CISA Flags Six Exploited Vulnerabilities in KEV Catalogsecurityonline.info· Security Online
- Citrix NetScaler: CISA warnt vor kritischer RCE-Lückeboerse-express.com· Boerse Express



