By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Six Exploited Vulnerabilities to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, citing evidence of active exploitation. This action mandates that federal agencies patch these vulnerabilities by a specific deadline to mitigate ongoing cyber threats. The inclusion in the KEV catalog signifies that these flaws have been actively exploited by malicious actors, posing a significant risk to government systems and data.
Among the newly added vulnerabilities is a high-severity security flaw impacting Citrix NetScaler ADC and NetScaler Gateway. This vulnerability, identified by CVE-2019-1068, allows for remote code execution, meaning an attacker could potentially run unauthorized code on a vulnerable system without needing physical access. The specific details of the exploit mechanism for CVE-2019-1068 were not fully disclosed in the announcement but its inclusion in the KEV catalog underscores its critical nature. Citrix NetScaler products are widely used for application delivery, secure remote access, and load balancing, making a vulnerability in these systems a prime target for attackers seeking to gain network access.
In addition to the NetScaler vulnerability, CISA also cataloged five other exploited flaws. These include vulnerabilities affecting Linux operating systems, Microsoft SQL Server, and other unspecified software. The inclusion of these diverse vulnerabilities highlights the broad range of targets that are currently under active attack. Federal agencies are now required to implement remediation measures for all six vulnerabilities within a specified timeframe, typically 14 days from the date of inclusion, though specific deadlines can vary. Failure to comply can result in increased scrutiny and potential security incidents.
The KEV catalog is a crucial tool for CISA to prioritize cybersecurity efforts across the federal government. By identifying and cataloging vulnerabilities that are known to be exploited in the wild, CISA enables agencies to focus their limited resources on the most pressing threats. The agency continuously monitors threat intelligence to identify new vulnerabilities that warrant inclusion in the KEV catalog. This proactive approach aims to reduce the attack surface of federal networks and protect sensitive government information from compromise. The addition of these six flaws serves as a reminder for all organizations, not just federal agencies, to review their security postures and ensure they are protected against actively exploited vulnerabilities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.