On August 26, 2026, CISA added 6 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2021-23758, CVE-2015-3246, CVE-2015-5287, CVE-2022-0995, CVE-2026-8452, CVE-2019-1068. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.
CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional · Ajax.NET Professional
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Federal due date
2026-09-09
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability
Red Hat · Libuser
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Federal due date
2026-09-09
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat · Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Federal due date
2026-09-09
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability
Linux · Kernel
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Federal due date
2026-09-09
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix · NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Federal due date
2026-08-29
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft · SQL Server
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Federal due date
2026-08-29
Ransomware use
Unknown
Added
2026-08-26
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
August 31, 2026: CVE-2026-81578, PaperCut NG/MF (PaperCut NG/MF Missing Authentication for Critical Function Vulnerability)
August 27, 2026: CVE-2026-66384, JFrog Artifactory (JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vu)
August 27, 2026: CVE-2026-53362, Linux Kernel (Linux Kernel Unspecified Vulnerability)
August 27, 2026: CVE-2023-49105, ownCloud ownCloud (ownCloud Improper Authentication Vulnerability)
August 25, 2026: CVE-2026-60004, Gitea Gitea (Gitea Code Injection Vulnerability)
August 24, 2026: CVE-2026-21962, Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in (Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Cont)
August 21, 2026: CVE-2026-73570, Synacor Zimbra Collaboration Suite (ZCS) (Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability)
August 20, 2026: CVE-2026-72530, TrueConf Server (TrueConf Server Code Injection Vulnerability)
August 20, 2026: CVE-2026-72529, TrueConf Server (TrueConf Server Missing Authentication for Critical Function Vulnerability)
August 18, 2026: CVE-2026-55040, Microsoft SharePoint (Microsoft SharePoint Weak Authentication Vulnerability)
August 18, 2026: CVE-2026-33824, Microsoft Internet Key Exchange (IKE) Service Extensions (Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabili)
August 17, 2026: CVE-2025-62593, Ray-Project Ray (Ray-Project Ray Code Injection Vulnerability)
August 11, 2026: CVE-2026-72898, Metabase Metabase (Metabase SQL Injection Vulnerability)
August 11, 2026: CVE-2026-68820, Microsoft Windows Ancillary Function Driver for WinSock (Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerabi)
August 11, 2026: CVE-2026-20349, Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) (Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Thre)