CISA just added four old local privilege escalation bugs to KEV. That is the interesting part.

Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022 — most of them local, none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.

In the last week of August 2026, CISA's Known Exploited Vulnerabilities catalogue picked up a cluster of entries that look, at first glance, like a filing error:

| CVE | Product | Class | Age | | --- | --- | --- | --- | | CVE-2015-3246 | Red Hat libuser | Race condition, local | 11 years | | CVE-2015-5287 | Red Hat ABRT | Symlink attack, local | 11 years | | CVE-2021-23758 | Ajax.NET Professional | Deserialization, RCE | 5 years | | CVE-2022-0995 | Linux kernel | Out-of-bounds write, local | 4 years |

[!] members only

The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included