The US Cybersecurity and Infrastructure Security Agency (CISA) recently expanded its Known Exploited Vulnerabilities catalog by adding six new flaws, highlighting the ongoing risk to government agencies and critical infrastructure organizations. This action, taken on August 26, underscores the urgency for these entities to implement necessary patches immediately.
Among the new entries are two high-severity vulnerabilities. The first, identified as CVE-2026-8452, affects Citrix's NetScaler ADC and NetScaler Gateway. This memory overflow vulnerability, discovered in June, carries a Common Vulnerability Scoring System (CVSS) severity rating of 8.8. If exploited, it could result in unpredictable system behavior or denial of service, particularly if the system is set up as a Gateway or a virtual server. Citrix has released patches to mitigate this risk.
The second vulnerability, CVE-2019-1068, is a remote code execution flaw in Microsoft SQL Server, originally discovered in 2019. Despite the long-standing availability of a patch, this vulnerability remains a target for threat actors. It allows attackers to run malicious code by sending specially crafted queries to an unpatched SQL server, potentially gaining control over the server's database engine service account.
CISA has mandated that government agencies apply patches for these vulnerabilities by August 29. Additionally, other older vulnerabilities added to the catalog must be addressed by September 9. This directive emphasizes the critical need for organizations to stay vigilant and proactive in their cybersecurity efforts.


