US Cybersecurity Agency Flags Six Actively Exploited Vulnerabilities, Including Citrix NetScaler Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively using them in real-world attacks. The list includes a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway, along with other vulnerabilities affecting Linux and SQL Server systems, such as a remote code execution bug (CVE-2019-1068) that has been known for several years.
The KEV catalog is used by government agencies and security teams worldwide as a trusted reference for vulnerabilities that require urgent attention. Being added to this list signals that a flaw is no longer theoretical—it's being exploited by cybercriminals right now, making unpatched systems a real and immediate risk.
For Australian small businesses using Citrix NetScaler products, Linux servers, or Microsoft SQL Server, this is a timely reminder to check whether these systems are up to date. Older, unpatched software remains one of the most common ways attackers gain a foothold in business networks, often leading to data theft, ransomware, or service disruption.