The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, adding six flaws that show evidence of active exploitation in the wild. Among the newly cataloged issues is a high severity security vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. This update signals an urgent need for organizations to identify and remediate these specific entry points within their network environments.
In addition to the Citrix networking issues, the update includes vulnerabilities found in Linux and Microsoft SQL Server. Specifically, CVE-2019-1068 is identified as a remote code execution vulnerability impacting SQL Server. These inclusions highlight that attackers continue to leverage older or well-known weaknesses in core infrastructure components to gain unauthorized access or execute malicious code across enterprise systems.
Federal agencies are required to address these vulnerabilities within specified timeframes to comply with binding operational directives. While these mandates primarily apply to government entities, the private sector is strongly encouraged to follow suit. Monitoring the KEV catalog allows IT departments to prioritize their patching schedules based on verified threat activity rather than theoretical risk scores alone.
For CIOs and IT directors, this development serves as a critical prompt to review patch management cycles for edge devices and database servers. Operations leaders should verify that internal inventory lists for NetScaler and SQL Server instances are current and that security teams have deployed the necessary vendor updates to mitigate these active threats.
The BroadVision view
These updates emphasize the persistent risk to foundational infrastructure like gateways and databases. IT leaders must shift from generic patching schedules to risk based cycles that prioritize vulnerabilities with proven exploitation history. Maintaining rigorous patch compliance through managed IT services ensures that high priority flaws are addressed before they can be leveraged for leveraged by external actors. /managed-it-services Teams weighing what to change first can review BroadVision's managed IT services.
