< Back to situation

[REVISION HISTORY]

CISA vulnerability exploitation and patching directives

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-28 14:17 UTC → 2026-09-10 15:37 UTC · added removed

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued directives to federal agencies regarding multiple actively exploited software vulnerabilities. In late August 2026, CISA ordered the patching of two vulnerabilities in TrueConf Server video conferencing software. These flaws, identified as CVE-2026-72529 and CVE-2026-72530, reportedly allow unauthorized remote attackers to execute scripts and gain control of host systems. Reports indicate the Ukrainian hacktivist group ‘Head Mare’ has utilized these flaws to deploy malware against energy, transport, and IT sectors in Russia and Belarus. Shortly thereafter, CISA added six more vulnerabilities to its Known Exploited Vulnerabilities catalog. This included a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway appliances (CVE-2026-8452), which researchers demonstrated could allow remote code execution as root. Threat actors have been observed using this flaw to deploy web shells. Additionally, the Chinese cybercrime group UAT-10147 has been linked to targeting global web servers in the education, media, technology, and gaming sectors using several of the newly cataloged vulnerabilities. On August 27, 2026, CISA expanded its catalog to include a Linux kernel flaw (CVE-2026-53362) in the IPv6 networking subsystem that allows for privilege escalation. The agency also flagged vulnerabilities in Microsoft SharePoint, Windows IKE Service Extensions, Broadcom VMware vCenter, and Apple macOS. Further advisories were issued for industrial control systems and operational technology, specifically targeting Xiiaozet LK100W devices, All-Line Equipment Fuel-Boss systems, and Rockwell Automation OTTO Fleet Manager. Separately, CISA Red Team tests identified security gaps in critical infrastructure where attackers successfully escalated privileges and moved laterally without triggering alerts. On September 9, 2026, CISA added new critical vulnerabilities to its catalog, including a high-severity flaw in Adobe Commerce and Magento (CVE-2026-75650). Known as ‘StyleSmuggler’, this vulnerability allows unauthenticated remote code execution and has been used since September 4 to deploy web shells and backdoors.

Versions

  1. 2026-09-10 15:37 UTC CISA vulnerability exploitation and patching directives
  2. 2026-08-28 14:17 UTC CISA vulnerability exploitation and patching directives
  3. 2026-08-27 14:10 UTC CISA vulnerability exploitation and patching directives

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.