CiberLATAMbywhalemate

CISA Adds Citrix, SQL Server CVEs to KEV

CISA added exploited flaws in August, including Citrix NetScaler, Microsoft SQL Server and VMware vCenter, to its KEV catalog.

Whalemate Labs · AI-assisted researchPublished:3 min read

In August 2026, CISA added several exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, with a focus on Citrix NetScaler, Microsoft SQL Server, Windows IKE, SharePoint and VMware vCenter. The move confirms ongoing activity against widely used enterprise products and sets remediation priorities for federal agencies and exposed organizations.

CISA added several exploited vulnerabilities to its Known Exploited Vulnerabilities catalog in August 2026, affecting widely used enterprise products such as Citrix NetScaler ADC and Gateway, Microsoft SQL Server, Microsoft Windows IKE Service Extensions, Apple macOS, Microsoft SharePoint and Broadcom VMware vCenter. Their inclusion in the KEV catalog confirms active exploitation and, in Citrix's case, triggered a particularly short federal remediation deadline.

What vulnerabilities did CISA add to the KEV in August?

CISA added CVE-2026-8452 in Citrix NetScaler, CVE-2019-1068 in Microsoft SQL Server, CVE-2026-33824 in Windows IKE, CVE-2026-65400 in macOS, CVE-2026-55040 in SharePoint, CVE-2026-59310 in VMware vCenter and CVE-2025-62593 in Ray. The list was also expanded with other exploited entries during the same period, according to summaries cited by Security Online, CyberSecureFox, FireCompass and Mallory.ai.

Security Online reported that CISA published six new exploited entries on Aug. 26, including Citrix NetScaler, Microsoft SQL Server, Red Hat and Ajax.NET. CyberSecureFox, for its part, said on Aug. 18 that four additional critical vulnerabilities were added, including Windows IKE, macOS, SharePoint and vCenter.

CVE Affected product KEV status Cited source
CVE-2026-8452 Citrix NetScaler ADC and Gateway Added on Aug. 26, 2026 CISA, Security Online, OpenVPN Blog
CVE-2019-1068 Microsoft SQL Server Added to KEV CISA, Security Online
CVE-2026-33824 Microsoft Windows IKE Service Extensions Added to KEV CISA, CyberSecureFox
CVE-2026-65400 Apple macOS, Screen Sharing Added to KEV CISA, CyberSecureFox
CVE-2026-55040 Microsoft SharePoint Added to KEV CISA, CyberSecureFox
CVE-2026-59310 Broadcom VMware vCenter Added to KEV CISA, CyberSecureFox, Tech-Insider
CVE-2025-62593 Ray Added to KEV CISA, CyberSecureFox

In the case of CVE-2026-8452, regulatory pressure was immediate. OpenVPN Blog said the KEV catalog set a mandatory remediation deadline for U.S. civilian federal agencies of Aug. 29, 2026, just three days after the entry was added. netVigilance also flagged it as critical and exploited in the wild, in line with Binding Operational Directive 26-04.

Why did Citrix NetScaler become the focus of the alert?

Because CVE-2026-8452 affects appliances configured with Gateway VPN or AAA virtual servers, two components that provide remote access, SSO portals and corporate authentication. BleepingComputer said the impact reaches infrastructure used by organizations for employee and third-party access, which makes the flaw a direct issue for Internet-exposed perimeters.

RedLegg said the vulnerability is being actively used for exploitation and that a confirmed proof of concept exists. It also published the affected version ranges, NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, data that helps size the potentially vulnerable footprint in enterprise and managed service environments.

Mallory.ai added operational context and said CVE-2026-8452 is being used to deploy web shells and perform reconnaissance. That same coverage placed NetScaler and SQL Server among high-value targets in recent campaigns, and recommended that U.S. private companies prioritize patching based on Internet exposure, asset criticality and business impact risk.

What does August's batch suggest?

The sequence shows CISA increasing pressure on critical enterprise infrastructure with remediation dates and priorities that vary by the level of exploitation detected. FireCompass documented that the CVEs added in August, including vCenter and Zimbra, arrived in batches with different deadlines, reinforcing a prioritization strategy for corporate platforms that concentrate sensitive services.

At the same time, HackerStorm said CVE-2026-59310 in VMware vCenter is a path traversal weakness that allows an attacker with network access to execute arbitrary code. Tech-Insider added that the flaw was seen in infrastructure across dozens of countries, with a focus on enterprise environments and cloud providers, and that three of the four critical vulnerabilities in the late-August batch received a CVSS score of 9.8.

Boerse Express also linked CISA's decision to Binding Operational Directive 26-04 and to active exploitation on the internet, consistent with the view that NetScaler holds a priority position because of its presence in corporate networks and U.S. public-sector systems.

Sources

View all