CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
What it means
CISA ha aggiunto sei vulnerabilità al KEV, tra cui CVE-2019-1068 e CVE-2026-8452, con evidenza di sfruttamento attivo. La CVE-2026-8452 è bersaglio di attacchi che includono shell web e comandi di scoperta. Alcune vulnerabilità non hanno informazioni sull'exploit attuale. CISA ha fissato scadenze per le patch.
Why it matters
Le PMI italiane potrebbero essere colpite da attacchi che sfruttano vulnerabilità note, con rischi di accesso non autorizzato, interruzione dei servizi e potenziale diffusione di malware. La mancanza di patch potrebbe esporre infrastrutture critiche a cyberattacchi.
Recommended actions
- Applicare immediatamente le patch per CVE-2019-1068 e CVE-2026-8452 entro il 29 agosto 2026
- Bloccare accessi non autorizzati a SQL Server e sistemi Linux
- Ridurre l'esposizione di servizi non necessari e applicare regole di firewall
- Monitorare attivamente i log per comandi di scoperta e shell web
- Eseguire backup regolari e verificare la loro integrità
- Implementare MFA per accessi critici e gestione delle identità
- Eseguire test di vulnerabilità per verificare l'effettiva esposizione
Sistemi e prodotti interessati
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
- Microsoft SQL Server
- Linux Kernel
- Red Hat Automatic Bug Reporting Tool (ABRT)
- Red Hat libuser
- Ajax.NET Professional (AjaxPro)
Cosa cercare (rilevamento)
- Ricerca di comandi come 'id' e 'echo' nei log di accesso
- Monitoraggio di tentativi di accesso non autorizzati a SQL Server
- Analisi di file PHP sospetti come 'x.php' e 'z.php'
- Controlli su accessi locali con privilegi elevati
- Rilevamento di tentativi di scrittura fuori dai limiti di memoria
- Analisi di accessi anomali a sistemi Linux
Estratto della fonte usato dal modello
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. CVE-2026-8452 - An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service. CVE-2022-0995 - An out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system. CVE-2015-5287 - A privilege escalation vulnerability in Red Hat Automatic Bug Reporting Tool (ABRT) that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. CVE-2015-3246 - A race condition vulnerability in Red Hat libuser that could allow an authenticated local user to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. CVE-2021-23758 - A deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro)
Potential operational benefits
- Riduzione della superficie esposta a vulnerabilità note
- Prevenzione di accessi non autorizzati e interruzioni dei servizi
- Miglioramento della risposta ai tentativi di attacco
- Aumento della conformità alle normative di sicurezza
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 27/08/2026 09:05
- MITRE ATT&CK
- T1078, T1486, T1059
- CVE
- CVE-2019-1068
- Classification
- High
Affected products and versions
The collector will check NVD and the available official vendor advisories.