ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Saturday, 3 October 2026: Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now

Good morning. Start with the vulnerabilities that attackers are already using. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 in Citrix NetScaler ADC as known to be exploited. The flaw carries a CVSS base score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — reachable over the network, no authentication and no user interaction required. CISA also lists CVE-2026-88772 in the same product as exploited; it scores 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Citrix's advisory names the fixed release as 13.1-64.23 for the 13.1 branch. Citrix's security bulletin (CTX697096) covers both. Move NetScaler ADC to 13.1-64.23 per the vendor advisory.

CISA's catalog also lists CVE-2026-86950 in Apple macOS as exploited, scoring 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), with user interaction required. Apple's advisory gives the fix in macOS 15.8.1. Apply it.

Google's Chrome release note addresses three flaws — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 — each scoring 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), fixed in Chrome 154.0.8037.92. These are not on CISA's KEV list. Update to 154.0.8037.92.

Read the full briefing →

Zoom out: Several of the day's reports touch China — Warlock's SharePoint campaign is attributed to a suspected China-linked actor, MI5 named China's state security service, and The Register reported exploitation attempts from a China-hosted IP.

Vulnerability in focus

CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.

Affected: macos.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • BleepingComputer: ShinyHunters hacker reportedly detained in Jordan, aiding FBI Read it
  • The Register: Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows Read it
  • The Hacker News: Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware Read it
  • SecurityWeek: doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures Read it
  • SecurityWeek: Fortra Patches Critical Vulnerabilities in BoKS Read it
  • The Hacker News: The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email