EXECUTIVE JUDGMENT // MATERIAL CHANGE SINCE AM
Inventory first, patch second, hunt before declaring victory.
Confirmed: CISA added CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995 and CVE-2026-8452 to the Known Exploited Vulnerabilities Catalog on August 26. KEV inclusion is evidence of exploitation, not a prediction. Assessment: teams should override ordinary CVSS- or EPSS-only queues where affected assets exist, with internet-facing NetScaler and exposed Ajax.NET endpoints at the front.
0–4 HOURSQuery CMDB, vulnerability scanners, EDR and cloud inventories for all six CVEs; identify NetScaler Gateway/AAA and Ajax.NET exposure.
TODAYApply vendor fixes or isolate affected assets. Preserve logs and review for exploitation before normalizing systems.
THIS WEEKHunt for privilege escalation and post-exploitation behavior; validate service-account, identity and edge-device containment playbooks.
01 // NEW KEV DELTA
What entered the confirmed-exploitation queue.
SEVERITY · HIGHCONFIDENCE · HIGHSOURCE · CISA KEV
| CVE / product | Exploitation consequence | Priority action | ATT&CK relevance |
CVE-2026-8452 Citrix NetScaler ADC/Gateway | Memory-buffer restriction flaw on Gateway or AAA configurations; edge-service compromise or disruption risk. | Apply Citrix fixed builds; review appliance crashes, restarts and anomalous Gateway/AAA requests. | T1190 Exploit Public-Facing Application |
CVE-2021-23758 Ajax.NET Professional | Unsafe deserialization can enable remote code execution in exposed .NET applications. | Find dependent applications, remove public exposure, patch/replace the component and inspect web-process child activity. | T1190; T1059 Command and Scripting Interpreter |
CVE-2019-1068 Microsoft SQL Server | Remote code execution risk in affected SQL Server deployments. | Confirm patch state and investigate unusual SQL service child processes, jobs and outbound connections. | T1210 Exploitation of Remote Services |
CVE-2022-0995 Linux kernel | Out-of-bounds write may permit local privilege escalation or denial of service. | Validate kernel/package remediation; hunt for suspicious unprivileged-to-root transitions and kernel instability. | T1068 Exploitation for Privilege Escalation |
CVE-2015-3246 / CVE-2015-5287 Red Hat libuser / ABRT | Local race-condition and privilege-escalation paths on legacy Linux estates. | Locate residual affected packages and unsupported hosts; patch, isolate or retire; review privileged account changes. | T1068 Exploitation for Privilege Escalation |
EPSS context: FIRST EPSS estimates 30-day exploitation probability and is updated daily. It is a prioritization input—not contrary evidence once CISA confirms exploitation. Do not use a stale or low model score to demote a KEV-listed asset.
02 // CARRYOVER · ACTIVE EXPLOITATION
Gitea remains a patch-and-hunt event.
Confirmed: CVE-2026-60004 entered KEV on August 25. A repository writer can abuse the diffpatch path to plant an executable Git hook; open registration can lower the practical access barrier. Gitea 1.27.1 contains the fix.
Action: upgrade, disable unnecessary self-registration, inspect hooks and Gitea service child processes, and rotate reachable secrets when compromise is suspected.
ATT&CK: T1190; T1059. CISA alert · vendor advisory
03 // CRITICAL INFRASTRUCTURE
Internet-exposed Siemens S7 PLCs remain an operational priority.
Confirmed: CISA, NSA, FBI, DOE and EPA report targeting of exposed or insufficiently segmented S7-series PLCs. Assessment: this is an architecture and access-control problem, not a single patch ticket.
Action: remove direct exposure, validate IT/OT segmentation, restrict engineering access and monitor control changes with operations approval.
ATT&CK for ICS: T0883 Internet Accessible Device. CISA AA26-231A
04 // AI-ENABLED THREAT
Operational evidence remains narrower than the sample volume.
Confirmed: Unit 42 reviewed 405 AI-associated malware samples; 12 appeared in production endpoint telemetry, while approximately 97% remained in research, validation or sandbox contexts. Existing behavioral and sandbox controls detected the production samples.
Assessment: AI lowers development friction and increases iteration speed, but defenders should prioritize runtime behavior, identity and egress over novelty labels.
Unit 42 analysis, August 25
05 // SOC & EDGE SIGNAL
Tuned detection and egress discipline decide the outcome.
CISA's two-SOC assessment showed full compromise in both environments, but baselining, tuned alerts and decisive containment changed defensive impact. SANS ISC separately reports SSRF hostname/DNS-rebinding evasions and FTP-banner command channels.
Action: validate resolved destinations after DNS resolution, block link-local/private metadata paths, alert on unexpected FTP, and prove every critical alert has an owner and containment authority.
CISA AA26-237A · SANS ISC, August 26
06 // RANSOMWARE & NATION-STATE WATCH
Identity, edge infrastructure and recovery systems stay in the blast radius.
CISA's Gunra advisory keeps recovery denial and data theft in focus. Google Threat Intelligence reporting on Russian-interest targeting using legitimate OAuth flows reinforces that valid login infrastructure can be weaponized for social engineering.
Action: separate backup administration from production identity, test immutable recovery, audit OAuth consent and require phishing-resistant MFA for privileged access.
CISA Gunra advisory · Google Threat Intelligence
INTELLIGENCE HYGIENE
Standards and platforms are not original evidence.
STIX 2.1 structures threat objects and relationships; TAXII 2.1 transports collections. MISP and OpenCTI aggregate, enrich and correlate. The originating government, vendor or researcher remains the evidence source, with timestamps and provenance preserved.
No live malware, exploit code, secrets, personal data or unredacted harmful indicators are published. Links lead only to public advisories and research.
SOURCE REGISTER // ACCESSED 26 AUGUST 2026
Primary and attributable sources.