Post
CRITICAL ⚡ MUST-KNOW

CISA Adds Six Actively Exploited Flaws to KEV Catalog, Including NetScaler, Linux, and SQL Server Bugs

· vulnerability · cve · rce

CISA added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list includes a high-severity Citrix NetScaler ADC and Gateway vulnerability, plus CVE-2019-1068, an older remote code execution flaw in SQL Server, alongside flaws affecting Linux systems.

Federal agencies are required to remediate KEV entries within CISA’s mandated timelines; other organizations should treat KEV additions as a signal to prioritize patching regardless of sector.