INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Six Exploited Flaws in Microsoft, Linux Products

| 2026-08-27 10:45 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day, urging government agencies and critical infrastructure organizations to patch them quickly. The vulnerabilities include memory overflow vulnerabilities in Microsoft products such as NetScaler ADC and NetScaler Gateway, remote code execution vulnerabilities in older versions of the same software, and several-year-old flaws that must be patched by September 9. CISA warned of these exploits on August 26, with six new KEV listings added to its catalog over the next two days, including a memory overflow vulnerability in Citrix products. The agency urged government agencies to apply patches for both vulnerabilities by August 29 and reminded them that Microsoft products must be patched by September 9 due to several-year-old flaws.
Technical Mitigations AI-generated
* Implement a secure patching strategy for all affected systems, including regular updates and patches from vendors to ensure timely resolution of the vulnerabilities. * Conduct thorough risk assessments and vulnerability scanning to identify potential entry points for attackers exploiting the identified vulnerabilities. * Educate users on how to prevent exploitation of these vulnerabilities by following best practices such as keeping software up-to-date, using strong passwords, and being cautious when opening emails or attachments from unknown sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

aj•••••.net
x•••••.php
z•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2015-3246CVE-2015-3246 CVE-2019-1068CVE-2019-1068 CVE-2026-8452CVE-2026-8452 CVE-2015-5287CVE-2015-5287 CVE-2022-0995CVE-2022-0995 CVE-2021-23758CVE-2021-23758
Target & Sectors
ASEAN ASEAN NORTH_AMERICA NORTH_AMERICA DACH DACH BENELUX BENELUX governmentgovernment mediamedia educationeducation technologytechnology
Incident Timeline
‎August 26
Threat actors used a six-year-old flaw in Microsoft products to target Citrix systems on August 26.
source_region United States
industry Government
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎Aug 27, 2026
Threat actors used a known vulnerability in Citrix products to gain unauthorized access.
‎2026/08/27
Threat actors used a race condition vulnerability in Red Hat libuser to target Citrix NetScaler ADC and NetScaler Gateway.
infrastructure Linux
organisation Red Hat
victims 5.1 Libuser condition vulnerability
organisation CVE-2015
organisation Red Hat Automatic Bug Reporting
organisation Microsoft
organisation CVE-2022-0995
organisation KEV
infrastructure Windows
organisation CVE-2021-23758
organisation Ajax
organisation CVE-2022-0995 Linux
organisation Shutterstock.com
organisation CVE-2022-0995 - An
organisation NetScaler ADC
organisation NetScaler Gateway
organisation CVE-2026
organisation Citrix NetScaler ADC
organisation KEVIntel
infrastructure 14.1-72
infrastructure 13.1-63
infrastructure 13.1
infrastructure 14.1-FIPS
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
infrastructure 13.1.37
infrastructure 8.8
organisation NetScaler
organisation Microsoft SQL
infrastructure 14.1 FIPS
infrastructure 13.1 FIPS
organisation the SQL
organisation NET Professional
organisation CVSS
organisation DoS
organisation ICA
organisation AAA
organisation SQL
organisation IP
financial 04 BOD
organisation CVE
organisation Aware
‎August 29
Microsoft, Linux and Red Hat software were found to have six newly discovered vulnerabilities that could be exploited by threat actors.
industry Government
‎August 29, 2026
Threat actors used a vulnerability in Microsoft products to target Citrix systems.
vulnerability CVE-2026-8452
vulnerability CVE-2019-1068
attribution Federal Civilian Executive Branch
attribution FCEB
‎September 9
Microsoft, Linux and Red Hat operating systems were found to have six previously unknown vulnerabilities.
target_region United States
‎September 9, 2026
Threat actors used a vulnerability in Citrix products to target Microsoft and Linux systems.
vulnerability CVE-2026-8452
vulnerability CVE-2019-1068
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
victims
5
Libuser Condition Vulnerability
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎14.1-72
Software Version
Metrics
infrastructure
‎13.1-63
Software Version
Metrics
infrastructure
‎13.1
Software Version
Metrics
infrastructure
‎14.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-NDcPP
Software Version
Metrics
infrastructure
‎13.1.37
Software Version
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
14
Fips
Metrics
infrastructure
13
Fips
Metrics
infrastructure
‎Windows
Affected Product
Metrics
financial
4
Bod