CISA put names on the public Known Exploited Vulnerabilities catalog this week. The list is the news. The dates are the news. This report does not describe how to trip a race, walk a symlink, or crash a gateway. The catalog already did the useful work: it told defenders which bugs are being used, and it put due dates on the cards.

On 26 August 2026 the catalog took six additions that Security Affairs, writing on 28 August, treated as the week’s clip. Primary is still CISA’s own page. The date is 30 August. The cards are still there.

CVE-2026-8452 is Citrix NetScaler ADC and NetScaler Gateway. CISA’s language is improper restriction of operations within the bounds of a memory buffer, which can lead to denial of service. Date added: 26 August 2026. Due date for federal civilian executive branch agencies: 29 August 2026. That due date is yesterday as of this Sunday file. Citrix’s support article is CTX696604. Print the ID. Print the product. Print the date. Do not print a packet.

CISA named the week’s exploited bugs and put due dates on the cards
The StandardDownload

CVE-2019-1068 is Microsoft SQL Server. CISA says remote code execution in the context of the SQL Server Database Engine service account. Added 26 August. Due 29 August. Microsoft’s advisory is on the MSRC portal under that CVE. A 2019 bug on a 2026 catalog is not a novelty act. It is the catalog doing what the catalog is for: naming what is being used, not what is fashionable.

CVE-2022-0995 is the Linux kernel, an out-of-bounds write. Added 26 August. Due 9 September 2026. CISA points at a kernel git commit, 93ce93587d36493f2f86921fa79921b3cba63fbb. The card notes the component shows up in more than one product. Suse and Red Hat are named on a related 27 August kernel card. The two kernel rows are not collapsed.

CVE-2015-5287 is Red Hat Automatic Bug Reporting Tool. Privilege escalation. Added 26 August. Due 9 September. CISA says the impacted product could be end-of-life and advises moving off it. CVE-2015-3246 is Red Hat libuser, a race condition, same add date, same due date, Red Hat article 1537873 on the card. CVE-2021-23758 is Ajax.NET Professional, deserialization of untrusted data. Added 26 August. Due 9 September. The github commit on the card is b0e63be5 on michaelschwarz/Ajax.NET-Professional. CISA’s EoL note is on that card too. Old names. Current catalog. That is the point of a KEV row.

Catalog board
A dark wall of CVE cards and due dates, no faces, a CISA catalog header on a screen.

On 27 August the catalog moved again. CVE-2026-53362 is Linux kernel, unspecified in CISA’s short title, privilege escalation via the IPv6 networking subsystem in the longer line. Date added 27 August. Due date 30 August 2026. That due date is today. Forensic triage required, per the card, yes. CISA lists several git.kernel.org stable commits. A repro is not pasted here. It is pasting the fact that the public catalog put a same-weekend due date on a kernel row.

CVE-2026-66384 is JFrog Artifactory. Added 27 August. Due 10 September 2026. CISA’s line is an improper limitation of a pathname to a restricted directory, writing data outside the intended Docker cache path under specific remote-repository conditions. An authenticated user is in that sentence. Authenticated is not a tutorial. It is the boundary CISA printed. JFrog is also on an earlier Artifactory cluster from the July incident other desks have already filed. This row is the 27 August KEV add. Keep the week.

Pierluigi Paganini at Security Affairs dated 28 August listed the 26 August six: two Red Hat, SQL Server, Ajax.NET Professional, Linux kernel CVE-2022-0995, Citrix CVE-2026-8452. That clip is a newspaper pointing at the catalog. The catalog is the primary. The live KEV page was checked on 30 August. The six are there. The 27 August kernel and Artifactory rows are there too. 1685 results on the page header the day we looked.

The action language on the current cards is Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, plus the forensics triage notes CISA links from the same cards. Apply vendor mitigations. Follow BOD 26-04. If mitigations are unavailable, the card’s cloud-service line is discontinue use. Stakeholders evaluate internet exposure. That is CISA’s sentence, not a pentest plan.

The rest of the craft stays off the page. No race walkthrough. No symlink recipe. No deserialization gadget list. No NetScaler crash how-to. No SQL Server engine-account payload. Glyph’s beat is the public news of the catalog: conferences, tools, research, and the list defenders already subscribe to. A KEV add is a tool. Due dates are a tool. Vendor advisories are a tool. Instructions for breaking in are not this report.

Federal civilian agencies live on those due dates. 29 August for SQL Server and NetScaler. 30 August for CVE-2026-53362. 9 September for the 2015 Red Hat pair, the 2022 kernel write, and Ajax.NET. 10 September for Artifactory. Private organizations are told, in the catalog’s own explainer, to use KEV as an input to their vulnerability management. Input, not a dare.

Citrix’s CTX696604 is how a gateway team finds the vendor sentence. MSRC is how a SQL Server team finds Microsoft’s sentence. Kernel git is how a distro team finds the commit. Red Hat’s article 1537873 is how a libuser owner finds Red Hat’s sentence. Github commit b0e63be5 is how an Ajax.NET owner finds the patch commit CISA cited. Print the pointers. Do not print the exploit.

A catalog that still names 2015 bugs in 2026 is a catalog that refuses fashion. ABRT and libuser are old. SQL Server 2019-1068 is old. Ajax.NET 2021-23758 is old. CVE-2026-8452 is this year’s NetScaler row. CVE-2026-53362 and CVE-2026-66384 are this year’s kernel and Artifactory rows. Old and new on one page is how KEV works. Known exploited, not newly assigned.

Due-date rail
A timeline rail of August and September due dates beside product names, paper tags, no people.

Forensic triage is a checkbox on some cards and not others. CVE-2026-53362 yes. CVE-2019-1068 yes. CVE-2026-8452 no. CVE-2022-0995 no. The checkbox is CISA’s, under BOD 26-04 implementation guidance. This is not a forensics shop. It is recording that the public list now tells you which of this week’s rows want that extra look.

This report records what the catalog did between 26 and 28 August, confirms it on 30 August, and keeps the how-to off the page. Six names on the 26th. Two more on the 27th. A Security Affairs clip on the 28th. Due dates that, for NetScaler and SQL Server, already passed yesterday, and for CVE-2026-53362 pass today. That is a good-news shape if you are a defender: the list is public, the dates are public, the vendor links are public. Patch to the card. Do not wait for a novel.

CISA’s explainer at the top of the catalog is the sentence kept here: the KEV catalog is the authoritative source of vulnerabilities that have been exploited in the wild, maintained so organizations can prioritize. Nominate a new KEV if you know one that is missing. That nomination line is CISA’s, not an invitation to dump a private bug here.

This report does not claim the six are the only rows this month. The page showed 1685. It claims these are the rows this week put in the window 23 to 30 August that a hacking correspondent can hang dates on without writing a break-in. 26 August. 27 August. 28 August the clip. 29 August two due dates. 30 August another due date and this file.

Leave the race in 2015. Leave the deserialization in the commit CISA already linked. Leave the buffer bounds in Citrix’s article. Bring the catalog into the paper. Names, products, add dates, due dates, vendor URLs. That is the whole craft printed here. The glasses stayed in the bag at DEF CON. The catalog stays in the open.