Government Advisory

CISA Flags Six More Vulnerabilities Under Active Attack

CISA · 26 Aug 2026
Key Takeaway Check whether your business uses any of the listed products, and apply the relevant security patches immediately rather than waiting for a scheduled update cycle.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that hackers are actively using these flaws to break into systems. The affected products include Red Hat's Libuser and Automatic Bug Reporting Tool, Microsoft SQL Server, Ajax.NET Professional, the Linux Kernel, and Citrix NetScaler ADC and Gateway.

While the KEV Catalog is primarily used to guide US federal agencies on urgent patching priorities, it's also a valuable early-warning resource for any business. If a vulnerability appears on this list, it means real-world attackers are exploiting it right now, not just that it's theoretically dangerous. Several of these flaws affect widely used enterprise software, including database servers and network gateway devices, which are common targets because they often sit at the edge of a company's network.

Australian small businesses using any of these products—particularly Microsoft SQL Server or Citrix NetScaler—should check with their IT provider or software vendor to confirm patches have been applied. Older or unsupported systems still running outdated Linux or Red Hat components may also be at risk if left unpatched.

CISA Known Exploited Vulnerabilities Patch Management

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.