CISA Adds Six Known Exploited Vulnerabilities to Catalog

2026-08-26T19:24:01Z5df8990834c1dcc442bd08b413512ddee91e571ab1071280dd1153c7192dbd50
CVE-2015-3246CVE-2015-5287CVE-2019-1068CVE-2021-23758CVE-2022-0995CVE-2026-21962CVE-2026-33824CVE-2026-55040CVE-2026-59310CVE-2026-60004CVE-2026-64849CVE-2026-65400CVE-2026-72529CVE-2026-72530CVE-2026-73570CVE-2026-8452Apple macOSCISACitrix NetScalerGiteaKEVKnown Exploited VulnerabilitiesLinux kernelMLflowMicrosoft SQL ServerMicrosoft SharePointOracle WebLogicRed HatTrueConfVMware vCenterZimbraactive exploitationurgent patchingvulnerability management

What happened

CISA alerts from August 19–26, 2026 report the addition of 16 vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Affected products include Red Hat Linux utilities, Microsoft SQL Server, Microsoft IKE and SharePoint, Ajax.NET Professional, the Linux kernel, Citrix NetScaler, Gitea, Oracle HTTP/WebLogic Server, Zimbra, TrueConf Server, MLflow, VMware vCenter, and Apple macOS. Organizations—especially FCEB agencies—should prioritize urgent remediation, assess internet-exposed systems, and investigate potential compromise in accordance עם

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
5df8990834c1dcc442bd08b413512ddee91e571ab1071280dd1153c7192dbd50
Enrichment time
2026-08-26T19:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.