All posts

Citrix NetScaler CVE-2026-8452 Exploited, Nine New KEV Adds

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, August 28, 2026

Citrix NetScaler CVE-2026-8452 is being exploited in the wild

The headline for the day is Citrix NetScaler. CVE-2026-8452, a memory buffer flaw in NetScaler ADC and NetScaler Gateway carrying a CVSS of 9.8, is now being exploited in the wild according to reporting from SecurityWeek and Help Net Security. This is a previously patched flaw, which means the fix already exists and the window to apply it is what separates an exposed appliance from a safe one.

CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on 2026-08-26. NetScaler sits on the perimeter, terminates VPN and gateway traffic, and holds credentials. That combination makes it a favorite target. If you run NetScaler ADC or Gateway, patching this is a patch-now item, not a patch-eventually item.

Nine new KEV additions across two days

Beyond Citrix, CISA added several vulnerabilities to the KEV catalog on 2026-08-26 and 2026-08-27. None are flagged ransomware-linked in these entries, but KEV placement means active exploitation is confirmed.

The list spans web-facing servers, development tooling, and older Linux and Red Hat issues that attackers still find useful for privilege escalation.

  • CVE-2023-49105, ownCloud improper authentication, CVSS 9.8, added 2026-08-27
  • CVE-2026-53362, Linux Kernel, CVSS 7.8, added 2026-08-27
  • CVE-2026-66384, JFrog Artifactory path traversal, CVSS 5.3, added 2026-08-27
  • CVE-2019-1068, Microsoft SQL Server remote code execution, added 2026-08-26
  • CVE-2021-23758, Ajax.NET Professional deserialization, CVSS 9.8, added 2026-08-26
  • CVE-2022-0995, Linux Kernel out-of-bounds write, CVSS 7.8, added 2026-08-26
  • CVE-2015-3246 and CVE-2015-5287, Red Hat Libuser and ABRT privilege escalation, added 2026-08-26

Hot movers worth attention

Among high-scoring exploited CVEs, CVE-2021-23758 (Ajax.NET Professional deserialization) tops the list with an EPSS of 0.8363 and is now KEV listed. Several ransomware-linked entries also rank high: CVE-2026-15409 in SonicWall SMA1000 (CVSS 10, ransomware-linked), CVE-2026-35273 in Oracle PeopleSoft PeopleTools (EPSS 0.9547, ransomware-linked), CVE-2026-45659 Microsoft SharePoint remote code execution (ransomware-linked), and CVE-2026-41940 in WebPros cPanel and WHM (EPSS 0.9853, ransomware-linked).

The SharePoint entry matters most to Microsoft 365 and on-prem administrators. It is KEV listed, ransomware-linked, and carries an EPSS of 0.7608. Tenable's edge infrastructure analysis reinforces the pattern: perimeter devices and gateways are where attackers concentrate, and CVE-2026-15409 shows up in that dataset.

What the press and advisories add

Qualys flagged CVE-2026-69414, a Windows Defender zero-day with no patch available, and noted CISA BOD 26-04 gives 14 days to act. Track that one for mitigation guidance since no fix is out yet.

On the industrial side, CISA published multiple ICS advisories on 2026-08-27, covering Applied Systems Engineering ASE2000, All-Line Fuel-Boss, Ebyte NA111-M, Mitsubishi Electric FA products and CNC series, and Xiiaozet LK100W. If any of these touch your OT environment, review them.

Do this first

Prioritize based on what is confirmed exploited and what is ransomware-linked.

  • Patch Citrix NetScaler ADC and Gateway for CVE-2026-8452 now; it is exploited in the wild and KEV listed
  • Confirm your Microsoft SharePoint patch state for CVE-2026-45659, which is ransomware-linked
  • Check ownCloud instances against CVE-2023-49105 and Microsoft SQL Server against CVE-2019-1068
  • Apply the mitigation guidance for CVE-2026-69414 since no patch exists yet
  • Use the free Microsoft Patch Tracker from Siemserva by Senserva to rank open Microsoft patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow the daily KEV additions above

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-08-28.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.