CISA adds six exploited flaws to KEV, including a NetScaler bug tied to web shells and 36 exploitation attempts in 12 days.

CISA adds actively exploited CVE-2026-21962 to KEV; the Oracle flaw can expose or alter critical data via unauthenticated HTTP access.

Citrix NetScaler vulnerability tracked as CVE-2026-8452 has been exploited in the wild to deliver web shells, according to security firms.