VulnOps
2026-09-19CISA added two known exploited vulnerabilities to its KEV Catalog today, escalating prioritization requirements for federal contractors and critical infrastructure operators. Multiple critical Linux kernel vulnerabilities (race conditions, out-of-bounds writes, and improper condition checks) alongside a NetScaler authentication bypass demonstrate active exploitation patterns requiring immediate patching assessment.
- →CISA KEV Catalog Additions: Additions trigger mandatory remediation timelines under federal compliance frameworks and establish baseline prioritization for vulnops teams managing federal-facing systems.
- →NetScaler CVE-2026-19490 Authentication Bypass: Critical perimeter security appliance vulnerability requires immediate patch deployment verification given the exposure of edge infrastructure to active exploitation.
- →Linux Kernel Critical Vulnerabilities (Race Condition, OOB Write, Improper Checks): Multiple kernel-level CVEs affecting system stability and cryptographic integrity demand rapid triage and patching prioritization across Linux-based infrastructure.
Immediately cross-reference today's CISA KEV additions against your asset inventory and establish patch timelines, while prioritizing NetScaler and Linux kernel vulnerability assessments in your remediation queue.
Release Date CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. [...] While BOD 26-04 appli
CVE-2026-19490 is a critical authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, rated 9.3 on CVSS v4.0. A remote attacker with no credentials can skip the login on an affected appliance configured as a Gateway or AAA virtual server. Citrix patched it on August 19, 2026. ### Which NetScaler versions are affected and what are the fixes? [...] Citrix appliances sit at the edge of the network, which is exactly why a login bypass in one is treated as an emergency and not a maintena
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.