← Back to blog

CISA Adds Six Actively Exploited Flaws to KEV Catalog

CISA has updated its Known Exploited Vulnerabilities catalog with six new flaws, including critical issues in NetScaler, Linux, and SQL Server. These vulnerabilities are already being exploited in the wild.

TL;DR

  • CISA added six new vulnerabilities to its KEV list due to active exploitation.
  • Included are high-severity bugs affecting Citrix NetScaler ADC/Gateway.
  • Other impacted systems include Linux and Microsoft SQL Server environments.
  • Organizations should prioritize patching these CVEs immediately.
  • The update emphasizes ongoing threats from unpatched enterprise software.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding six new security flaws. These additions come with confirmed evidence of active exploitation, making them critical priorities for organizational patch management.

Among the most notable entries is a high-severity remote code execution flaw in Citrix NetScaler ADC and Gateway platforms. Given their widespread use in enterprise environments, these vulnerabilities pose significant risk if left unaddressed. Organizations using affected systems should evaluate their exposure and apply mitigations immediately.

Critical Vulnerability in Citrix NetScaler

  • CVE-2019-1068 allows remote code execution on vulnerable NetScaler ADC and Gateway instances.
  • Citrix products are commonly used for secure remote access, increasing potential impact.
  • Active exploitation makes this a priority for immediate remediation efforts.

Broader Impacts Across Enterprise Systems

  • Additional vulnerabilities affect Linux-based systems and Microsoft SQL Server.
  • All six flaws have been observed in real-world attacks according to CISA data.
  • Inclusion in the KEV catalog triggers compliance deadlines for federal agencies.
  • Private sector organizations should treat KEV-listed vulnerabilities as high-priority risks.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.