CISA's list that day

26 August 2026

On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in Red Hat Libuser, Red Hat Automatic Bug Reporting Tool, Microsoft SQL Server and 3 other products. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2019-1068Remote Code ExecutionMicrosoft SQL ServerPatch nowForensic triage required by CISA0.57
CVE-2015-3246Race ConditionRed Hat LibuserPatch this weekMetasploit module; verified Exploit-DB entry0.08
CVE-2015-5287Privilege EscalationRed Hat Automatic Bug Reporting ToolPatch this weekMetasploit module; verified Exploit-DB entry0.05
CVE-2021-23758Deserialization of Untrusted DataAjax.NET Professional Ajax.NET ProfessionalPatch this weekMetasploit module; EPSS 0.830.83
CVE-2022-0995Out-of-Bounds WriteLinux KernelPatch this weekMetasploit module0.09
CVE-2026-8452Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScaler ADC and NetScaler GatewayPatch soon0.01

Other changes that day

  1. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inEdited: required action.