INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Red Hat Linux Kernel Exploit Vulnerability
| 2026-08-28 09:07 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The situation is critical as a series of vulnerabilities have been identified in various software products, including Microsoft SQL Server and Red Hat Automatic Bug Reporting Tool. These vulnerabilities can be exploited to gain unauthorized access, execute code, or escalate privileges, posing significant threats to organizations and individuals. The most recent incidents include the automatic bug reporting tool privilege escalation vulnerability CVE-2019-1068 and the Linux Kernel Out-of-Bounds Write Vulnerability CVE-2022-0995. Affected products range from Microsoft SQL Server to Citrix NetScaler ADC and NetScaler Gateway, highlighting a broader scope of vulnerabilities that require immediate attention. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing the need for swift action by organizations to patch these weaknesses before they can be exploited.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent privilege escalation vulnerabilities, such as those found in Red Hat Automatic Bug Reporting Tool (CVE-2019-1068) and Microsoft SQL Server Remote Code Execution Vulnerability (CVE-2021-23758).
* Regularly update and patch operating systems, applications, and firmware to ensure that known vulnerabilities are addressed before they can be exploited.
* Configure network devices with proper restrictions on memory buffers and use of privileged access to prevent improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8452).
* Monitor systems for signs of exploitation and take prompt action if any vulnerabilities are detected, such as patching affected software and implementing security controls to prevent unauthorized access.
* Educate users on how to properly use and configure network devices, including the importance of following best practices for secure coding and input validation.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
aj•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8452CVE-2026-8452
CVE-2026-3055CVE-2026-3055
CVE-2026-19490CVE-2026-19490
CVE-2015-5287CVE-2015-5287
CVE-2026-4368CVE-2026-4368
CVE-2019-1068CVE-2019-1068
CVE-2015-3246CVE-2015-3246
CVE-2026-19489CVE-2026-19489
CVE-2021-23758CVE-2021-23758
CVE-2022-0995CVE-2022-0995
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
November 2021
Threat actors used a known exploit of the Citrix NetScaler vulnerability to target affected systems.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, the U.S. cybersecurity agency
has flagged 23 Citrix vulnerabilities
as exploited in the wild, seven of them also abused by ransomware gangs.
general_metric
23 Citrix vulnerabilities
Since November 2021, the U.S. cybersecurity agency
has flagged 23 Citrix vulnerabilities
as exploited in the wild, seven of them also abused by ransomware gangs.
March 23
Threat actors used Citrix NetScaler Professional to target U.S. CISA on March 23, just days before abusing two other vulnerabilities, CVE-2026-3055 and CVE-2026-4368.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-3055
"
While these security flaws have not been flagged as exploited in attacks, Citrix
urged admins
to patch two other NetScaler vulnerabilities (
CVE-2026-3055
and
CVE-2026-4368
) on March 23, just days before attackers
began abusing them in the wild
.
vulnerability
CVE-2026-4368
"
While these security flaws have not been flagged as exploited in attacks, Citrix
urged admins
to patch two other NetScaler vulnerabilities (
CVE-2026-3055
and
CVE-2026-4368
) on March 23, just days before attackers
began abusing them in the wild
.
March 30
Threat actors used a known exploited vulnerability in Citrix NetScaler to target U.S. federal agencies on March 30.
Click on any entity below to view its context and source!
attribution
Known Exploited
CISA
added
the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
tactic
T1588.006 - Vulnerabilities
CISA
added
the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
attribution
KEV
CISA
added
the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
vulnerability
CVE-2026-3055
CISA
added
the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
attribution
CISA
CISA
added
the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
2026/08/28
Microsoft SQL Server Remote Code Execution Vulnerability.
Click on any entity below to view its context and source!
organisation
Microsoft
Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758
Ajax.
organisation
Red Hat Automatic Bug Reporting
CVE-2015-5287 is a privilege escalation bug in Red Hat Automatic Bug Reporting Tool that could allow local users with certain permissions to gain higher privileges via a symlink attack on a predictable file.
organisation
the SQL
CVE-2019-1068 is a remote code execution flaw in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
organisation
CVE-2021-23758
CVE-2021-23758 (CVSS score not specified in the KEV notice) is a deserialization of untrusted data vulnerability in Ajax.
organisation
KEV
CVE-2021-23758 (CVSS score not specified in the KEV notice) is a deserialization of untrusted data vulnerability in Ajax.
organisation
Ajax
CVE-2021-23758 (CVSS score not specified in the KEV notice) is a deserialization of untrusted data vulnerability in Ajax.
organisation
NetScaler
While Citrix said
in June
that threat actors could
only exploit the flaw in denial-of-service (DoS) attacks
, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers
to gain remote code execution as root
on unpatched NetScaler instances.
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Citrix NetScaler ADC and NetScaler
Citrix urges admins to patch new NetScaler flaws as soon as possible.
organisation
DoS
While Citrix said
in June
that threat actors could
only exploit the flaw in denial-of-service (DoS) attacks
, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers
to gain remote code execution as root
on unpatched NetScaler instances.
The second, a high-severity memory overflow security flaw tracked as
CVE-2026-19489
, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.
infrastructure
Linux
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Citrix NetScaler ADC and NetScaler
CVE-2022-0995 (CVSS score not specified in the KEV notice) is an out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
organisation
NET Professional
NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
organisation
Microsoft SQL
NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
organisation
Citrix NetScaler
NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the "add lsn group.*sipalg.
organisation
Known Exploited
NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
organisation
CVE-2022-0995
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Citrix NetScaler ADC and NetScaler
organisation
NetScaler ADC
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Citrix NetScaler ADC and NetScaler
Tracked as
CVE-2026-8452
, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.
organisation
CVE-2026-8452
CVE-2026-8452 (CVSS score not specified in the KEV notice) is an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service and has been observed under active exploitation in the wild.
organisation
Citrix NetScaler ADC
CVE-2026-8452 (CVSS score not specified in the KEV notice) is an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service and has been observed under active exploitation in the wild.
organisation
NetScaler Gateway
CVE-2026-8452 (CVSS score not specified in the KEV notice) is an improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service and has been observed under active exploitation in the wild.
Tracked as
CVE-2026-8452
, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.
organisation
AAA (Authentication, Authorization
Tracked as
CVE-2026-8452
, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
organisation
Auditing
Tracked as
CVE-2026-8452
, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
organisation
CVE-2026
Citrix has yet to update the
security advisory for the CVE-2026-8452 vulnerability
to acknowledge that it's now being targeted in the wild.
Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the "add lsn group.*sipalg.
organisation
lsn group.*sipalg
Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the "add lsn group.*sipalg.
organisation
SIP ALG
The second, a high-severity memory overflow security flaw tracked as
CVE-2026-19489
, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.
organisation
NAT
The second, a high-severity memory overflow security flaw tracked as
CVE-2026-19489
, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.
organisation
AAA
The most severe of the two, tracked as
CVE-2026-19490
, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.
"This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server," Citrix said at the time.
organisation
ICA
The most severe of the two, tracked as
CVE-2026-19490
, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.
organisation
Gateway
"
At the moment, Internet threat watchdog Shadowserver tracks
over 22,000 NetScaler ADC
appliances and
nearly 1,800 Gateway
instances exposed online.
organisation
The ShadowServer Foundation
The ShadowServer Foundation now tracks
over 22,000 NetScaler ADC
and
nearly 1,800 NetScaler Gateway instances
exposed online.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
infrastructure
14.1-73
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
infrastructure
13.1-63
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
infrastructure
13.1-37
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
organisation
NetScaler ADC FIPS
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
infrastructure
14.1 FIPS
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
infrastructure
73.32 FIPS
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler Gateway security bulletin
, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
Citrix warned
on Wednesday.
organisation
Auth
*) string and Auth or VPN vserver ('add authentication vserver .
organisation
Secure Private Access Hybrid
SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.
August 29, 2026
The U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog due to the deadlines set for federal agencies to fix CVE-2019-1068 and CVE-2026-8452 by August 29, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2019-1068
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
vulnerability
CVE-2026-8452
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
attribution
CVE-2026
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
August 29
Citrix NetScaler appliances were ordered to be secured by August 29 due to the addition of CVE-2026-8452 flaw in CISA's Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
attribution
Known Exploited
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
tactic
T1588.006 - Vulnerabilities
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
KEV
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
vulnerability
CVE-2026-8452
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
CVE-2026
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
FCEB
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
attribution
Federal Civilian Executive Branch
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
general_metric
26 Binding Operational Directive
Citrix NetScaler appliances exposed online (Shadowserver)
On Monday, CISA
added
the CVE-2026-8452 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by
Binding Operational Directive (BOD) 26-04
.
September 9, 2026
The U.S. CISA ordered federal agencies to fix the Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler vulnerabilities by August 29, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2019-1068
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
vulnerability
CVE-2026-8452
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
attribution
CVE-2026
CISA orders federal agencies to fix the flaws CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, while the remaining must be addressed by September 9, 2026.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Ke…
NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452
Citrix NetScaler ADC and NetScaler
CVE-2022-0995 (CVSS score not specified in the KEV notice) is an out-of-bounds memory write vulnerability in Linux Kernel that could allow a local user to gain privileged access or cause a denial of service on the system.
Metrics
infrastructure
14.1-73
Software Version
…ed customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or late…
Metrics
infrastructure
13.1-63
Software Version
…ler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later,…
Metrics
infrastructure
13.1-37
Software Version
…and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that customers review the
official NetScaler ADC and NetScaler…
Metrics
infrastructure
14
Fips
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 F…
Metrics
infrastructure
73
Fips
…NetScaler Gateway 14.1-73.32 or later,
NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
NetScaler ADC FIPS 14.1-73.32 FIPS or later,
or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable
"We strongly recommend that cus…
Intelligence Sources
BleepingComputer
2026-08-20
Citrix urges admins to patch new NetScaler flaws as soon as possible
BleepingComputer
BleepingComputer
2026-08-27
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
BleepingComputer
Security Affairs
2026-08-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-29T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
Microsoft
entity
13x
attribution
Attributing Entity
NET Professional
authority
10x
vulnerability
Exploited CVE
CVE-2019-1068
cve
8x
timeline
Temporal Reference
August 29, 2026
date
4x
tactic
MITRE ATT&CK Technique
T1588.002 - Tool
technique
3x
tactic
Cyber Operation Type
Privilege Escalation
tactic
3x
infrastructure
Software Version
14.1-73
version
2x
general metric
Citrix Vulnerabilities
23
citrix vulnerabilities
2x
infrastructure
Fips
14
fips
Contextual Telemetry
Context Block
11 METRICS
general metric
Escalation Vulnerability
1,068
escalation vulnerability
infrastructure
Affected Product
Linux
software
general metric
Gateway Improper Restriction
3,246
gateway improper restriction
industry
Targeted Sector
Government
sector
general metric
Binding Operational Directive
26
binding operational directive
general metric
Adc Appliances
22,000
adc appliances
general metric
Gateway Instances
1,800
gateway instances
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Gateway
63
gateway
general metric
Ndcpp
13
ndcpp
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.