← All briefings

Citrix NetScaler ADC and NetScaler Gateway · Microsoft SQL Server · Linux Kernel

Date: 2026-08-27 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Six new CISA KEV entries dominate today’s report, including actively exploited vulnerabilities in Microsoft SQL Server (CVE-2019-1068), the Linux Kernel (CVE-2022-0995), and Citrix NetScaler ADC/Gateway (CVE-2026-8452) — the latter with a 72-hour remediation deadline of 2026-08-29. BSI has issued new critical advisories for Vercel Next.js and TYPO3 Extensions, and new high-severity advisories for Ubiquiti UniFi Protect, JFrog Artifactory, Apache Tomcat, and Veeam ONE. Microsoft SharePoint (CVE-2026-63520) has been upgraded to STATUS CHANGE: active exploitation with a public PoC chain now confirmed. A new AitM phishing toolkit (NovaCookies) targeting Microsoft 365 sessions has been disclosed.


Critical Vulnerabilities

CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway

  • Severity: Not yet published (CISA KEV confirmed)
  • EPSS: Not yet scored — newly added
  • Technical detail: An improper restriction of operations within the bounds of a memory buffer in Citrix NetScaler ADC and NetScaler Gateway can lead to denial of service. NetScaler ADC and Gateway are widely deployed as enterprise network edge and VPN appliances; memory buffer vulnerabilities in these products have historically been chained with authentication bypass flaws for full compromise. Affects all supported appliance form factors.
  • Exploitation status: Actively exploited — CISA KEV added 2026-08-26.
  • Remediation: Apply Citrix patches immediately. CISA federal deadline: 2026-08-29. Restrict management interface access to trusted networks. Review NetScaler logs for anomalous traffic patterns.

CVE-2019-1068 — Microsoft SQL Server (RCE)

  • Severity: Not yet published in KEV entry (CISA KEV confirmed)
  • EPSS: Not yet scored in this context — newly added to KEV
  • Technical detail: A remote code execution vulnerability in Microsoft SQL Server allows an attacker to execute code in the context of the SQL Server Database Engine service account. Exploitation requires an authenticated database connection, but SQL Server instances exposed to internal networks with weak credential hygiene are broadly at risk. This is a legacy vulnerability now confirmed exploited in the wild — likely being leveraged in post-compromise lateral movement scenarios.
  • Exploitation status: Actively exploited — CISA KEV added 2026-08-26.
  • Remediation: Apply the relevant SQL Server cumulative update. CISA federal deadline: 2026-08-29. Audit SQL Server exposure, enforce least-privilege service accounts, and review authentication logs for anomalous connections.

CVE-2022-0995 — Linux Kernel (Out-of-Bounds Write)

  • Severity: Not yet published in KEV entry (CISA KEV confirmed)
  • EPSS: Not yet scored in this context — newly added to KEV
  • Technical detail: An out-of-bounds memory write vulnerability in the Linux Kernel allows a local user to gain privileged access or cause denial of service. Affects a broad range of Linux distributions. Local privilege escalation via kernel vulnerabilities is a standard post-initial-access technique; this KEV addition indicates active use in real-world attack chains.
  • Exploitation status: Actively exploited — CISA KEV added 2026-08-26.
  • Remediation: Apply current kernel updates for your distribution. CISA federal deadline: 2026-09-09. Prioritize internet-facing Linux systems and container hosts.

CVE-2026-63520 — Microsoft SharePoint (RCE Chain) — STATUS CHANGE

  • New development: Active exploitation of a two-vulnerability RCE chain confirmed by threat intelligence firm Defused; a public PoC is now circulating. Previously reported 2026-08-26 as patch-required with no confirmed exploitation.
  • Update: Treat as actively exploited. Accelerate patching of on-premises SharePoint instances to August 2026 Patch Tuesday level. Block external access to SharePoint admin interfaces where possible and hunt for web shell indicators.

CVE-2026-65956 — KubePi (Unauthenticated SSO API Exposure)

  • Severity: CVSS 10.0
  • EPSS: 0.0 — newly published
  • Technical detail: In KubePi versions up to and including 1.6.15, SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login interface, allowing unauthenticated access. KubePi is a Kubernetes multi-cluster management panel; unauthenticated access to SSO configuration in a Kubernetes management plane is a critical risk, potentially enabling full cluster takeover. Upgrade to 2.0.0 or later.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Upgrade KubePi to ≥ 2.0.0. Restrict management panel access to internal/VPN networks immediately.

ONGOING:

  • CVE-2026-60004 (Gitea): CISA KEV deadline today 2026-08-28 — patch to ≥ 1.27.1 without further delay; audit Git hook directories.
  • CVE-2021-23758 (Ajax.NET Professional): KEV added 2026-08-26, deadline 2026-09-09 — discontinue use or upgrade; deserialization RCE.
  • CVE-2015-3246 / CVE-2015-5287 (Red Hat Libuser / ABRT): KEV added 2026-08-26, deadline 2026-09-09 — apply RHEL patches; EoL products should be decommissioned.
  • CVE-2026-77533 (UniFi Protect): CVSS 9.9 command injection — upgrade to ≥ 7.2.105; see European Advisories.
  • CVE-2026-21962 (Oracle WebLogic): KEV deadline today 2026-08-27 — patch immediately if not done.
  • CVE-2026-68820 (Windows AFD/Lazarus): KEV deadline passed — apply August Patch Tuesday.
  • CVE-2026-73570 (Zimbra ZCS): KEV deadline passed, 270+ compromised — audit for web shells.
  • CVE-2026-64849 (MLflow SSRF): KEV deadline 2026-09-02 — patch and audit IAM.
  • CVE-2026-19478 (GitLab): Actively exploited — upgrade to 19.0.6 / 19.1.4 / 19.2.2.
  • CVE-2026-69414 (Microsoft Defender ShieldBreak): No patch available — monitor MSRC.

European Advisories

BSI — New critical advisories (2026-08-26):

WID-SEC-2026-3027 (Vercel Next.js — kritisch/NEW): Multiple vulnerabilities allow unauthenticated remote code execution in Vercel Next.js. Next.js is extremely widely deployed in enterprise web applications and internal tooling. Apply the latest Next.js security release immediately; review deployment configurations for exposure.

WID-SEC-2026-3003 (TYPO3 Extensions — kritisch/NEW): Multiple vulnerabilities across various TYPO3 extensions allow RCE, SQL injection, privilege escalation, XSS, information disclosure, and DoS. TYPO3 is heavily used in German public sector and enterprise web presences. Audit installed extensions and apply all available security updates.

BSI — New high-severity advisories (2026-08-26):

WID-SEC-2026-3028 (Ubiquiti UniFi OS — hoch/NEW): Covers CVE-2026-77533 (CVSS 9.9 command injection) and related flaws — see Critical Vulnerabilities for detail. Upgrade UniFi Protect to ≥ 7.2.105.

WID-SEC-2026-3026 (JFrog Artifactory — hoch/NEW): Multiple vulnerabilities allow security bypass, SSRF, data manipulation, information disclosure, and DoS for authenticated remote attackers. JFrog Artifactory is a critical component in enterprise software supply chains. Apply current JFrog patches.

WID-SEC-2026-3007 (Apache Tomcat — hoch/NEW): Multiple vulnerabilities allow security bypass, privilege escalation, data manipulation/disclosure, and DoS. Apply current Apache Tomcat security releases.

WID-SEC-2026-3008 (Veeam ONE — hoch/NEW): An unauthenticated remote attacker can bypass security controls in Veeam ONE. Veeam ONE is widely used for backup monitoring in European enterprises; apply vendor patches promptly.

WID-SEC-2026-3029 (GitLab): covered in Critical Vulnerabilities ONGOING.

WID-SEC-2026-3013 (Google Chrome) and WID-SEC-2026-3010 (Gitea): covered in yesterday’s report — apply patches per prior guidance.

BSI — Updated advisories: FreeBSD (hoch), DNN (hoch), libTIFF (hoch), Jenkins/Jenkins Plugins (hoch), NGINX/NGINX Plus (multiple — hoch), FasterXML Jackson (hoch), FreeRDP (hoch), Apache HTTP Server (hoch), Bouncy Castle BC-JAVA (hoch) — apply current vendor patches per prior guidance.


Active Threats and Campaigns

NovaCookies AitM PhaaS — Microsoft 365 Session Hijacking (NEW): A subscription-based ($320/month) adversary-in-the-middle phishing toolkit called NovaCookies proxies Microsoft 365 sign-ins to capture authenticated session tokens, bypassing MFA. Disclosed by Island Research. Hunt for anomalous OAuth token issuance, unexpected session origins, and conditional access policy gaps. Complements the previously reported Mirage2FA campaign targeting the same platform.

Indeed Spyware Campaign (NEW): Researchers have identified a global malware campaign targeting users of the Indeed job platform via trojanized interview applications. Relevant for organizations with active recruitment processes or BYOD policies. Brief HR and recruiting staff; block execution of unsigned application packages from external sources. (Heise Security)

SLEEPWALKER Backdoor (NEW): A newly documented Windows backdoor DLL remains dormant until triggered by a single crafted network packet, then executes commands in a custom 23-instruction bytecode language. Unsigned 64-bit DLL, side-loaded into a host process. No attribution confirmed. Add detection for unsigned DLL side-loading and anomalous inbound packet patterns to EDR/NDR rules.

Nimbus Manticore (IRGC) — Expanded Toolset (NEW): Group-IB reports the Iranian IRGC-affiliated group Nimbus Manticore has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneler. Described as among the most active Iranian APT groups in 2026. European organizations in energy, defense, and government sectors should review for indicators associated with this actor.

ONGOING:

  • Microsoft SharePoint RCE chain: Now actively exploited with public PoC — see Critical Vulnerabilities STATUS CHANGE.
  • Mirage2FA PhaaS (M365): Hunt for OAuth anomalies; review conditional access policies.
  • Norway Government DDoS: Ongoing disruption to government digital infrastructure; Russian attribution under investigation.
  • Zimbra ZCS active exploitation: 270+ servers compromised — audit for web shells immediately.
  • UAT-10147 / SPECTRE, AnonyMousKIT, npm ClickFix infrastructure: No new developments; maintain prior mitigations.

Security News and Context

  • FBI disrupts Chinese QTFY espionage infrastructure: The DoJ announced disruption of QScan and QTRouter platforms operated by Chinese state-sponsored group QTFY (linked to Nanjing Xinjiuwei Network Technology), used to target US critical infrastructure. (The Hacker News, Bleeping Computer)
  • Boston Scientific cyberattack: Medical technology firm Boston Scientific confirmed a cyberattack causing global operational disruptions to IT systems. (Bleeping Computer)
  • Bitkom study — German cyber damage: A new Bitkom study reports billions in damages to German companies from cyberattacks; Germany’s domestic intelligence chief warns against underestimating systemic dependencies. (Heise Security)
  • CISA red team report: CISA published results of simultaneous red team assessments against two critical infrastructure organizations — both fully compromised at domain level; one detected nothing. (The Hacker News)

  1. Citrix NetScaler ADC/Gateway (CVE-2026-8452): Apply Citrix patches immediately — CISA KEV deadline 2026-08-29; restrict management interface to trusted networks.
  2. Microsoft SQL Server (CVE-2019-1068): Apply SQL Server cumulative update — CISA KEV deadline 2026-08-29; audit for exposed instances and weak service account credentials.
  3. Gitea (CVE-2026-60004): CISA KEV deadline today 2026-08-28 — patch to ≥ 1.27.1 without further delay; audit Git hook directories.
  4. Oracle WebLogic (CVE-2026-21962): KEV deadline today 2026-08-27 — patch immediately if not yet done.
  5. Microsoft SharePoint (CVE-2026-63520): Active exploitation with public PoC confirmed — accelerate patching; block external admin interface access; hunt for web shells.
  6. Linux Kernel (CVE-2022-0995): Apply distribution kernel updates — CISA KEV deadline 2026-09-09; prioritize internet-facing and container hosts.
  7. KubePi (CVE-2026-65956): Upgrade to ≥ 2.0.0; restrict management panel to internal/VPN networks immediately.
  8. Vercel Next.js / TYPO3 Extensions (BSI WID-SEC-2026-3027, WID-SEC-2026-3003): Apply latest security releases; audit TYPO3 extension inventory.
  9. JFrog Artifactory / Apache Tomcat / Veeam ONE: Apply vendor patches per BSI advisories WID-SEC-2026-3026, WID-SEC-2026-3007, WID-SEC-2026-3008.
  10. Continue remediation of previously reported items: CVE-2026-73570 (Zimbra — deadline passed), CVE-2026-64849 (MLflow — deadline 2026-09-02), CVE-2026-68820 (Windows AFD — deadline passed), CVE-2026-19478 (GitLab), CVE-2026-69414 (Defender ShieldBreak — no patch).