CISA Adds Six Actively Exploited Vulnerabilities Spanning Microsoft, Linux, Red Hat and Citrix

The US cybersecurity agency’s Known Exploited Vulnerabilities catalogue grew by six entries on 26 August, covering widely deployed enterprise platforms.

AI-generated illustration depicting policy for the story: CISA Adds Six Actively Exploited Vulnerabilities Spanning Microsoft, Linux, Red Hat and Citrix

Summary

  • CISA confirmed active exploitation of six new vulnerabilities across Microsoft, Linux, Red Hat and Citrix products.
  • The additions were made to the KEV catalogue on 26 August, triggering mandatory remediation timelines for US federal agencies.
  • The affected platforms are common across enterprise and government environments, broadening the potential exposure for organisations outside the US as well.
  • Security teams should treat KEV listings as a reliable signal of real-world attacker interest, not just a compliance checkbox.
  • Patch prioritisation and compensating controls should be reviewed immediately for any affected systems in scope.

Six vulnerabilities, four major vendors

CISA updated its Known Exploited Vulnerabilities catalogue on 26 August with six newly confirmed entries affecting products from Microsoft, Linux, Red Hat and Citrix. The catalogue is maintained as a living reference of flaws that threat actors have demonstrated they can and do exploit in practice. An entry is not theoretical — it reflects observed activity in the wild.

What the KEV listing means in practice

For US federal civilian agencies, a KEV listing carries a binding remediation deadline under the relevant CISA directive. For everyone else, it serves as one of the more reliable early-warning signals available without a threat intelligence subscription. When CISA adds a flaw, it is because exploitation has already begun — meaning organisations that have not yet patched are operating in a window where attackers are actively looking for vulnerable instances.

The vendor spread warrants attention

The fact that these six entries span four distinct vendors — Microsoft, Linux, Red Hat and Citrix — is worth pausing on. This is not a single supply-chain event or a coordinated disclosure from one product family. Each entry reflects separate exploitation activity across different technology stacks. For security teams managing heterogeneous environments, that means the remediation effort is likely spread across multiple teams, change windows and risk owners.

Microsoft and Citrix remain high-value targets

Microsoft and Citrix products are perennial fixtures in the KEV catalogue, and this update continues that pattern. Both vendors have large installed bases in enterprise and government settings, which makes their vulnerabilities attractive to a wide range of threat actors — from opportunistic ransomware groups to more targeted intrusion campaigns. Citrix in particular has seen sustained attacker interest in its remote access and application delivery products over recent years.

Linux and Red Hat entries reflect broader OS-level risk

The inclusion of Linux and Red Hat vulnerabilities is a reminder that server-side and infrastructure risk is not solely a Windows problem. Many organisations apply more relaxed patching cadences to Linux systems on the assumption that they present a smaller attack surface. Confirmed exploitation evidence challenges that assumption directly.

Context for the wider security community

Australia’s own cyber agency, the Australian Signals Directorate, regularly references and aligns with CISA advisories, and many Australian enterprises and critical infrastructure operators use the KEV catalogue as an input to their vulnerability management programmes. While the binding directive applies only to US federal bodies, the practical risk to any organisation running affected products is the same regardless of jurisdiction.

Why it matters

The KEV catalogue is one of the most actionable public threat signals available to security leaders. Six entries in a single update across four major vendors signals broad attacker activity rather than a narrow campaign. CISOs should treat this as a prompt to verify patch status on affected systems, confirm that vulnerability scanning is current, and satisfy themselves that compensating controls exist where immediate patching is not feasible. The diversity of affected platforms — spanning Windows-adjacent, Linux, and remote access infrastructure — means this is unlikely to be a gap confined to a single team.

What to do now

  • Cross-reference the six newly added CVEs against your asset inventory to identify exposed systems across Microsoft, Linux, Red Hat and Citrix environments.
  • Prioritise patching for any assets confirmed as in scope, treating CISA’s active-exploitation confirmation as an elevated risk signal.
  • Where patching cannot be completed immediately, identify and document compensating controls and set a firm remediation deadline.
  • Ensure vulnerability scanning tools are up to date with signatures for the newly listed CVEs.
  • Brief relevant system owners and infrastructure teams on the affected vendors so remediation is not siloed within a single team.

Sources