CVE Tools
Back to blog

CISA's Newest KEV Batch Has an 11-Year-Old Bug in It — But Not All Six Are the Same Story

Cisco Talos tied four decade-plus-old Linux and .NET bugs to an AI-tooling Chinese crew. The other two CVEs added to KEV in the same CISA alert — a Citrix NetScaler RCE and a 2019 SQL Server flaw — have nothing to do with that campaign.

CISA's Newest KEV Batch Has an 11-Year-Old Bug in It — But Not All Six Are the Same Story. Cisco Talos tied four decade-plus-old Linux and .NET bugs to an AI-tooling Chinese crew. The other two CVEs
CISA's Newest KEV Batch Has an 11-Year-Old Bug in It — But Not All Six Are the Same Story. Cisco Talos tied four decade-plus-old Linux and .NET bugs to an AI-tooling Chinese crew. The other two CVEs

On August 26, 2026, CISA added six CVEs to its Known Exploited Vulnerabilities catalog in a single alert. Read as one press release, it looks like one story: a wave of active exploitation, split across two remediation deadlines. It isn't one story. It's three, and they don't share an attacker.

6CVEs added to KEV on Aug 26, 2026one CISA alert
11 yrsage of the oldest bug in the batchCVE-2015-3246, published 2015
3 storiesdistinct, unconnected exploitation campaignsnot one coordinated actor

The batch, sorted correctly

CVEProductCVSSPublishedWho's exploiting itFCEB deadline
CVE-2015-3246Red Hat libuser5.12015UAT-10147 (Cisco Talos)Sep 9, 2026
CVE-2015-5287Red Hat ABRT7.82015UAT-10147 (Cisco Talos)Sep 9, 2026
CVE-2022-0995Linux kernel (watch_queue)7.82022UAT-10147 (Cisco Talos)Sep 9, 2026
CVE-2021-23758Ajax.NET Professional8.12021UAT-10147 (Cisco Talos)Sep 9, 2026
CVE-2019-1068Microsoft SQL Server8.82019Unattributed — no public detailAug 29, 2026
CVE-2026-8452Citrix NetScaler ADC/Gateway9.82026Unattributed — opportunistic scanningAug 29, 2026

Story one: an AI-tooling crew farming bugs from 2015–2022

Cisco Talos published its report on UAT-10147 on August 20, 2026 — a Chinese-speaking group Talos assesses, with moderate-to-high confidence, is financially motivated (SEO fraud and data theft) and part of an emerging class of actors using agentic AI to scale offensive operations against internet-exposed Windows and Linux web servers.

  • DeepAudit for automated source-code vulnerability scanning, found installed on the group's own management server
  • PentestGPT to dynamically scan target web servers and run proof-of-concept exploits
  • AI-generated documentation and four companion Python scripts (check_paths.py, deploy_implant.py, deploy_shell.py, exfil.py) built around the ysoserial deserialization framework, including a full ASP.NET ViewState RCE guide
  • Known malware/tools in the operation: Metasploit, Meterpreter, QuasarRAT disguised as svchosts.exe, EfsPotato, Gh0stCringe, NoodleRAT, and a custom implant Talos calls SPECTRE

Talos found a target list of roughly 170,000 URLs on the group's command-and-control open directory, split into 17 files of about 10,000 each, aimed at government, education, media, technology and gaming targets. Compromised servers were located in Brazil, Bolivia, China, Canada and Vietnam. None of the four CVEs behind this campaign are new — the newest, CVE-2022-0995, is three and a half years old; the oldest two are from 2015.

Stories two and three: NetScaler's severity flip, and a 2019 bug nobody's explained

CVE-2026-8452 is the batch's other critical, and its history is its own story. Citrix patched it on June 30, 2026, in bulletin CTX696604, describing it narrowly as a memory overflow that "may lead to unpredictable behavior or denial of service" on NetScaler ADC/Gateway appliances configured as a Gateway VPN or AAA virtual server — and stated it had observed no exploitation at the time.

What Citrix said on patch day vs. what researchers proved six weeks later

Citrix, June 30, 2026 (CTX696604)
  • "Memory overflow" leading to "unpredictable behavior or denial of service"
  • No exploitation observed
  • Own CVSS 4.0 vector stopped short of code execution
watchTowr Labs, August 14, 2026
  • Binary-diffed patched vs. unpatched nsppe engine, found undocumented size checks
  • Root cause: heap buffer overflow in SAML SignedInfo canonicalization, via the PrefixList attribute of InclusiveNamespaces
  • Demonstrated a write-what-where primitive escalating to root-level RCE
  • NVD independently scored it CVSS 3.1 9.8 — critical, not DoS

CVE-2026-8452: from patch-day DoS label to root shell

  1. Attacker sends crafted SAML SignedInfo (PrefixList / InclusiveNamespaces)
  2. nsppe packet engine parses it — heap buffer overflow (CWE-119)
  3. Write-what-where primitive established
  4. pitboss crash-monitor process bypassed
  5. Root-level remote code execution, unauthenticated
  6. Webshells x.php / z.php dropped; id, echo run for recon

Threat-intel outfits Defused Cyber and Previdian (formerly KEVIntel) picked up the resulting exploitation independently — Previdian logged 36 exploitation attempts over a 12-day window from 12 unique IPs spread across ten countries (Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., Vietnam). That geographic spread reads as opportunistic "pray and spray" scanning, not a single attributable campaign — and as of writing, no group has claimed it.

The pattern that does connect them

Years between publication and this KEV addition
CVE-2015-324611CVE-2015-528711CVE-2019-10687CVE-2021-237585CVE-2022-09954CVE-2026-84520
LabelValue
CVE-2015-324611
CVE-2015-528711
CVE-2019-10687
CVE-2021-237585
CVE-2022-09954
CVE-2026-84520

Attribution aside, the batch does share one real thing: five of the six patches have existed for years, in some cases over a decade, and someone found unpatched machines to exploit them on anyway. Our own database still lists CVE-2026-8452 as has_exploit: false and puts its EPSS score at just 1.6% — a live illustration of the gap between what a scoring model predicts and what a CISA telemetry-backed KEV addition confirms already happened. CVSS tells you the ceiling of the damage; EPSS tells you a probability; only KEV tells you it's already been used.

What to actually do with this alert

  1. Patch by deadline group, not by narrative: CVE-2019-1068 and CVE-2026-8452 are due August 29; the four UAT-10147 CVEs are due September 9 under BOD 26-04.
  2. If you run NetScaler ADC/Gateway as a Gateway VPN or AAA virtual server, treat CVE-2026-8452 as unauthenticated root RCE, not the DoS Citrix's June bulletin described — versions 14.1-72.61 (FIPS), 13.1-63.18 and 13.1-37.272 carry the fix.
  3. Don't assume decade-old Linux privesc bugs are irrelevant because they're old — UAT-10147 is proof they're still a working toolkit against unpatched, internet-facing servers.
  4. Don't wait for attribution to patch. Two of these six CVEs have no named actor at all and are exploited anyway.

KEV and scoring data current as of 2026-09-03