- CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, including a Citrix NetScaler flaw under active attack
- Threat actors are dropping web shells named “x.php” and “z.php” while exploiting CVE-2026-8452, according to security firms
- Cisco Talos linked four of the vulnerabilities to a Chinese cybercrime group targeting web servers across multiple sectors
The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday added six flaws to its Known Exploited Vulnerabilities catalog, including a high-severity Citrix NetScaler ADC and NetScaler Gateway vulnerability, CISA confirmed. Security firms Defused Cyber and Previdian warned of active exploitation efforts targeting CVE-2026-8452, with attackers dropping web shells named “x.php” and “z.php” and running discovery commands. “The attackers were dropping a web shell named ‘x.php’ and ‘z.php,’ and running discovery commands, like ‘id’ and ‘echo,'” Previdian said in a social media post.
Telemetry data shows 36 exploitation attempts have been detected over the past 12 days from 12 unique attacker IP addresses originating from Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam. The addition of CVE-2022-0995, CVE-2015-5287, CVE-2015-3246, and CVE-2021-23758 to the catalog follows a report from Cisco Talos, which detailed a Chinese cybercrime group known as UAT-10147 that is targeting Windows and Linux web servers globally across education, media, technology, and gaming sectors.
Meanwhile, there is currently no public information on how CVE-2019-1068 is being exploited in the wild. CISA is urging Federal Civilian Executive Branch agencies to apply fixes for CVE-2019-1068 and CVE-2026-8452 by August 29, 2026, and for the remaining flaws by September 9, 2026. The additions coincide with CISA’s release of a new vulnerability review that delves into the root causes of insecure software and practical steps organizations can take to prevent exploitation.
According to the agency’s analysis of CVE records from 2024 and 2025, injection weaknesses emerged as the most dominant category, accounting for 7,701 CVEs in 2024 and 21,019 CVEs in 2025. CISA stressed that threat actors are exploiting simple, known software vulnerabilities that remain persistent in exposed assets and that artificial intelligence is being used to automate exploitation efforts.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
