The US Cybersecurity and Infrastructure Security Agency (CISA) has added six exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, a move that underscores the ongoing threat posed by unpatched software flaws. The newly listed bugs affect NetScaler, Linux, SQL Server, and other systems, putting organizations in various industries at risk of cyber attacks.
The KEV catalog is a centralized database of vulnerabilities that have been actively exploited in the wild. CISA uses it to inform organizations about the most pressing security threats and encourage them to apply patches or take other necessary steps to mitigate risks. The inclusion of these six flaws in the KEV catalog serves as a stark reminder of the importance of timely vulnerability management.
NetScaler, a load balancing solution developed by Citrix, is one of the platforms affected by the newly listed vulnerabilities. CVE-2021-22984, an arbitrary code execution bug, has been exploited in attacks targeting enterprises and government agencies. Linux systems are also at risk due to two flaws: CVE-2019-11815, a privilege escalation vulnerability, and CVE-2016-10007, which allows attackers to bypass security restrictions.
Microsoft SQL Server is another software platform impacted by the KEV additions. CVE-2021-24205, an information disclosure bug, has been exploited in attacks targeting databases used by organizations across various sectors. The inclusion of these vulnerabilities in the KEV catalog sends a clear message: if you’re using any of these platforms and haven’t applied patches or updates, you may be vulnerable to cyber attacks.
The threat landscape is becoming increasingly complex due to the growing number of software flaws that are being exploited by attackers. CISA’s decision to add these six vulnerabilities to its KEV catalog highlights the need for organizations to prioritize vulnerability management and implement robust security measures. This includes regular patching, network segmentation, and employee education on cybersecurity best practices.
The recent additions to the KEV catalog serve as a warning to all organizations: if you haven’t taken steps to address known vulnerabilities, you’re putting your data and systems at risk of cyber attacks. It’s essential for businesses and government agencies to regularly review their security posture, apply patches and updates in a timely manner, and invest in robust cybersecurity measures to protect against the evolving threat landscape.
In practical terms, organizations should prioritize patching and updating all affected systems as soon as possible. This includes not only the six vulnerabilities listed in the KEV catalog but also any other known exploits that may be lurking on your network. By staying vigilant and taking proactive steps to address software flaws, you can reduce the risk of a devastating cyber attack.
Source: The Hacker News — 2026-08-27