CISA's list that day
26 August 2026
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in Red Hat Libuser, Red Hat Automatic Bug Reporting Tool, Microsoft SQL Server and 3 other products. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2019-1068Remote Code Execution | Microsoft SQL Server | Patch nowForensic triage required by CISA | 0.57 | ||
| CVE-2015-3246Race Condition | Red Hat Libuser | Patch this weekMetasploit module; verified Exploit-DB entry | 0.08 | ||
| CVE-2015-5287Privilege Escalation | Red Hat Automatic Bug Reporting Tool | Patch this weekMetasploit module; verified Exploit-DB entry | 0.05 | ||
| CVE-2021-23758Deserialization of Untrusted Data | Ajax.NET Professional Ajax.NET Professional | Patch this weekMetasploit module; EPSS 0.83 | 0.83 | ||
| CVE-2022-0995Out-of-Bounds Write | Linux Kernel | Patch this weekMetasploit module | 0.09 | ||
| CVE-2026-8452Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler ADC and NetScaler Gateway | Patch soon | 0.01 |