CISA Adds Six Vulnerabilities to KEV Catalog With Federal Deadlines as Early as August 29
On August 26, 2026, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate Citrix NetScaler CVE-2026-8452 and Microsoft SQL Server CVE-2019-1068 by August 29 and four others by September 9. Researchers at watchTowr demonstrated a pre-authentication root-level code execution path for CVE-2026-8452, though Citrix's own bulletin describes the flaw as a memory-overflow denial-of-service issue and no named attack campaign has been publicly confirmed. A separate critical authentication bypass in NetScaler, CVE-2026-19490, has fixed builds available along with a conditional mitigation, but it was not among the six KEV additions.