Threat Intelligence

US Cybersecurity Agency Flags Six Actively Exploited Vulnerabilities, Including Citrix NetScaler Flaw

The Hacker News · 27 Aug 2026
Key Takeaway Check if your business uses Citrix NetScaler, Linux, or SQL Server systems, and apply available security patches immediately to close known, actively exploited vulnerabilities.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively using them in real-world attacks. The list includes a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway, along with other vulnerabilities affecting Linux and SQL Server systems, such as a remote code execution bug (CVE-2019-1068) that has been known for several years.

The KEV catalog is used by government agencies and security teams worldwide as a trusted reference for vulnerabilities that require urgent attention. Being added to this list signals that a flaw is no longer theoretical—it's being exploited by cybercriminals right now, making unpatched systems a real and immediate risk.

For Australian small businesses using Citrix NetScaler products, Linux servers, or Microsoft SQL Server, this is a timely reminder to check whether these systems are up to date. Older, unpatched software remains one of the most common ways attackers gain a foothold in business networks, often leading to data theft, ransomware, or service disruption.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.