Six CVEs, two deadlines
CISA added six CVEs to KEV on August 26. Four trace to a published Talos report and got 14 days. Two appear in no research at all, and got three.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
I was cross-referencing the August 26 KEV additions against a Cisco Talos report, expecting a clean match. I got four out of six [1][4].
CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog on August 26, 2026 [1]. Two of them are from 2015. That was going to be the story, until I noticed the due dates.
Four of the six are due September 9. The other two are due August 29, three days after they were added [2].
What happened
Six entries, spanning eleven years of CVE identifiers [1][2]:
| CVE | Product | Deadline |
|---|---|---|
| CVE-2015-3246 | Red Hat libuser | September 9 |
| CVE-2015-5287 | Red Hat ABRT | September 9 |
| CVE-2021-23758 | Ajax.NET Professional | September 9 |
| CVE-2022-0995 | Linux kernel | September 9 |
| CVE-2019-1068 | Microsoft SQL Server | August 29 |
| CVE-2026-8452 | Citrix NetScaler | August 29 |
Fourteen days for one group, three for the other, from the same batch on the same day.
That split is not arbitrary. BOD 26-04 replaced the old flat remediation window with a table, and CISA’s implementation guidance publishes the rule that generates the dates: where CISA determines the vulnerability is present on a publicly exposed asset, the technical impact is total, and it is automatable by an adversary, the due date reflects a three-day deadline [3]. Everything else gets longer.
So the catalog is telling you something it does not spell out. Two of these six were assessed as internet-reachable, totally compromising, and automatable. Four were not.
The part that surprised me
Here is what I expected to find, and did not.
The four with fourteen days are all named in Talos’s report on UAT-10147, a Chinese-speaking, financially motivated group Talos discovered in early 2026 and assesses with moderate-to-high confidence to be part of an emerging class of operators using agentic AI to scale offensive work [4]. CVE-2015-3246, CVE-2015-5287, CVE-2021-23758 and CVE-2022-0995 are all in there.
CVE-2019-1068 and CVE-2026-8452 are not. I searched the full report. Neither identifier appears anywhere in it [4].
Which produces an inversion worth sitting with. The two vulnerabilities on the
shortest possible federal deadline are the two with the least public evidence
behind them. There is no research write-up naming them. Microsoft’s own record
for CVE-2019-1068 still reports exploited as No and was last revised on
December 3, 2019 [7]. Citrix’s bulletin for CVE-2026-8452 describes the
impact in prose as denial of service, then scores it 8.8 under CVSS v4 with
confidentiality rated High [5]. NVD scores the same flaw 9.8, with
confidentiality and integrity both High [6]. CISA’s catalog entry describes it
as denial of service [2].
So the vendor advisory disagrees with its own vector, NVD disagrees with the vendor, and the entry carrying the shortest deadline in the batch is the one nobody characterises the same way twice.
I have gone looking behind a KEV entry before and found the evidence chain thinner than the entry implied. This is the opposite problem: entries with a shorter deadline and no public trail at all.
None of that means CISA is wrong. CISA sees exploitation telemetry that vendors and researchers do not, which is the entire reason the catalog exists. It does mean that the entries you can verify against public research are not the ones demanding action first, and if your patch prioritisation waits for a write-up to appear, you will always be late on exactly the entries that matter most.
Why this matters more than the age suggests
The age is not the interesting part. The stage is.
Both 2015 entries are local privilege escalation on Linux. libuser is a race
condition allowing an authenticated local user to corrupt /etc/passwd; ABRT
lets a local user escalate through a symlink attack on a predictably named file
[2]. Neither gets an attacker into anything. They are what an attacker uses once
already inside.
Talos states it plainly: having obtained access, the actor escalates privileges using a broad arsenal of known local privilege escalation exploits [4]. The way in came from web applications, Zimbra, AjaxPro, Nacos and Telerik UI, all with fixes published between 2019 and 2022 [4].
Local privesc is the category that gets deferred, and it gets deferred for a reason that sounds correct: it requires prior access. So it drops below the internet-facing work every quarter, forever. CVE-2015-3246 scores 5.1 under CVSS v3.1, a medium, with high attack complexity and no network vector. It would never surface on a severity-ranked list. It is now in the exploited catalog, eleven years after it was disclosed.
The prior access an attacker needs is the thing your other CVEs give them.
Technical breakdown: how the chain runs
Sequence reconstructed from Talos’s reporting [4]. Descriptive only.
- ReconnaissanceScanning against a target list Talos measured at roughly 170,000 URLs for known-vulnerable web applications
- Initial accessExploiting unpatched internet-facing software, including Zimbra, AjaxPro, Nacos and Telerik UI, all with fixes available since 2022 or earlier
BREAK THE CHAIN HERE
Patch the entry CVEs Talos names: CVE-2022-27925, CVE-2021-23758, CVE-2021-29441, CVE-2021-29442 and CVE-2019-18935. Alert on web application worker processes spawning shells or writing new handler files into web roots. - FootholdPlacing ASHX web shells to retain access to the compromised web server
- Privilege escalationOn Linux hosts, running local exploits against unpatched kernel and service flaws to move from a web service account to root
BREAK THE CHAIN HERE
This is what the August 26 batch covers. Patch CVE-2022-0995, CVE-2015-5287 and CVE-2015-3246, then confirm your EDR agent actually runs on those hosts. Alert on service accounts acquiring privileges they have never held before. - Defence evasionOn Windows targets, adding IIS directories to Windows Defender exclusions through PowerShell and registry changes before deploying payloads
BREAK THE CHAIN HERE
Alert on any write to Defender exclusion paths in the registry. Exclusion changes are rare, administrator-driven, and one of the higher quality signals available on a Windows estate. - PersistenceInstalling remote access tooling, including QuasarRAT, Gh0stCringe and NoodleRAT
- AI-assisted adaptationUsing agentic frameworks such as PentestGPT and DeepAudit to refine and troubleshoot exploits that fail in the target environment
- ImpactLoading malicious BadIIS modules to hijack search traffic for SEO fraud, alongside data theft
Two of those three breaks are patching. The third is a detection you can build this week without waiting for anyone to ship a fix, which makes it the one worth starting with.
What defenders should do Monday morning
Immediate, today. Check whether you run NetScaler as a Gateway or AAA virtual server, which are the preconditions Citrix publishes for CVE-2026-8452; fixed builds are 14.1-72.61 and later, 13.1-63.18 and later of 13.1, and 13.1.37.272 for the FIPS and NDcPP branches [5]. Inventory SQL Server instances still on unpatched 2019-era builds. Both carry a three-day federal clock, which tells you how CISA rates the exposure.
Near term, this week. Patch the four with the September 9 date. Then do the part that is easy to skip: verify the Linux hosts in scope are hosts you can actually see. A privilege escalation patch you deploy through an agent that is not installed is a patch you did not deploy, which is what a rule on 60% of hosts is 60% coverage is about.
Structural, this quarter. Stop treating local privilege escalation as a
lower tier by default. Rank it against the exploitability of your internet-facing
estate, because that is what supplies the foothold the escalation needs. And
start reading the dueDate field in the KEV feed as a risk signal rather than a
compliance artifact. You are already downloading it.
The checklist
- NetScaler configured as Gateway or AAA vserver, on a fixed build.
- SQL Server inventory reconciled against 2019 patch levels.
- CVE-2022-0995, CVE-2015-5287, CVE-2015-3246 patched on Linux.
- Agent coverage confirmed on those same Linux hosts, by count not by policy.
- Defender exclusion registry writes alerting.
- IIS loaded-module baseline captured, additions alerting.
- KEV
dueDatemapped into your own severity ranking.
The catalog is an intelligence product
We treat KEV as a list of things to patch. It is also a record of what CISA believes about exposure, impact and automatability for every entry, encoded in a date field that most vulnerability programmes throw away on import.
The August 26 batch shows what that costs. A team reading only the CVE list sees six vulnerabilities, four of them old, and reasonably concludes this is a routine housekeeping update. A team reading the dates sees that two entries were flagged as internet-reachable and totally compromising with a seventy-two hour window, and that neither has a public write-up anyone can consult.
The gap between those two readings is three days wide, and for two of these entries it closes on August 29.
FREQUENTLY ASKED
- Why do two of the six have a three-day deadline and four have fourteen?
- BOD 26-04 replaced the old flat window with a table that varies by risk. CISA's implementation guidance spells out the rule: if CISA determines the vulnerability sits on a publicly exposed asset, the technical impact is total, and it is automatable by an adversary, the due date reflects a three-day deadline. Everything else gets longer. So the three-day pair is not more severe by CVSS, it is the pair CISA judged to be exposed, total and automatable. CISA does not publish those per-CVE determinations, so you can see the output and not the working.
- Does the batch mean the Talos campaign is why CISA added these?
- CISA does not say so, and the honest answer is that four of the six line up and two do not. CVE-2015-3246, CVE-2015-5287, CVE-2021-23758 and CVE-2022-0995 are all named in Talos's UAT-10147 report. CVE-2019-1068 and CVE-2026-8452 appear nowhere in it. Coverage that describes the whole batch as following the Talos research is right about two thirds of it.
- We are not a federal agency. Do the due dates mean anything to us?
- The dates are only binding on FCEB agencies, but the risk assessment behind them is free and better than most internal triage. A three-day date is CISA telling you it believes the flaw is internet-reachable, gives total control, and can be automated. That is a more useful prioritisation signal than a CVSS score, and it costs nothing to read the dueDate field you are already downloading.
- Two of these are from 2015. Why would anyone still care?
- Because they are not entry points. Both are local privilege escalation on Linux, which means the actor already had a foothold and used them to become root. Local privesc is the category that gets deferred most often, on the reasoning that it needs prior access. UAT-10147 obtains prior access by exploiting web applications, then reaches for an escalation bug that is old precisely because nobody prioritised it.
- How do I know if the NetScaler flaw applies to me?
- Citrix publishes the preconditions. CVE-2026-8452 requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server, and Citrix gives the configuration strings to search for. Fixed builds are 14.1-72.61 and later, 13.1-63.18 and later of 13.1, 14.1-72.61 FIPS and later, and 13.1.37.272 and later for 13.1-FIPS and 13.1-NDcPP.
REFERENCES
- [1]CISA Adds Six Known Exploited Vulnerabilities to CatalogPRIMARY
- [2]Known Exploited Vulnerabilities Catalog (JSON feed, catalog version 2026.08.27)PRIMARY
- [3]BOD 26-04 Implementation Guidance: Prioritizing Security Updates Based on RiskPRIMARY
- [4]UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsVENDOR RESEARCH
- [5]NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 (CTX696604)PRIMARY
- [6]CVE-2026-8452 detailPRIMARY
- [7]CVE-2019-1068 security update guide entryPRIMARY
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗