started · updated
CISA flags multiple actively exploited vulnerabilities in Linux, Citrix, and Microsoft software
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, impacting a wide range of enterprise software and critical infrastructure.
Key additions include a Linux kernel vulnerability (CVE-2026-53362) affecting the IPv6 networking subsystem, which allows for local privilege escalation. CISA has also flagged a high-severity Citrix NetScaler ADC and NetScaler Gateway flaw (CVE-2026-8452) that can lead to denial-of-service conditions. Additionally, four major flaws in Microsoft Windows/SharePoint, Broadcom VMware vCenter, and Apple macOS have been identified as actively exploited, with several carrying critical severity ratings.
CISA's recent red team assessments further highlighted systemic weaknesses in critical infrastructure, noting instances where organizations failed to detect intrusions even after attackers had escalated privileges and moved laterally through networks. Other advisories have addressed vulnerabilities in industrial fuel-management platforms, autonomous mobile-robot systems, and utility communications equipment.
Entities
Apple · CISA · Cisco Talos · Citrix · Cybersecurity and Infrastructure Security Agency · Linux · Microsoft · NetScaler