ITsecurity Daily
Daily Briefing
Citrix NetScaler zero-days under active exploitation top a heavy day for defenders
Good morning. CISA said it is amplifying Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 and CVE-2026-88778. In a separate alert CISA added two of them to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation: CVE-2026-88771, which CISA describes as an improper input validation vulnerability, and CVE-2026-88772, which CISA describes as an improper restriction of operations within the bounds of a memory buffer.
The Hacker News reported that security firm watchTowr said on September 26 that two unpatched NetScaler zero-days allowing remote code execution are being actively exploited in the wild, and that Citrix has not confirmed the flaws or published a fix. BleepingComputer reported that Citrix administrators are being warned to shut down NetScalers over the two exploited zero-days, with patches expected next week. If you run NetScaler ADC or Gateway, match your appliances against the CVEs above; BleepingComputer's guidance to take appliances offline until a fix ships is the mitigation on record while no patch exists.
SecurityWeek reported that CISA added Microsoft SharePoint flaw CVE-2026-65660 to its KEV catalogue, now exploited in attacks, with a federal patching deadline of September 28. Treat that deadline as the clock for SharePoint operators.
Zoom out: Three separately exploited flaws — in Citrix NetScaler, Microsoft SharePoint and Oracle PeopleSoft — were being acted on at the same time.
Elsewhere
- The Register: Certainties in life: Death, taxes, and critical Citrix vulns under attack Read it
- Help Net Security: If you do one security check this quarter, make it agent memory Read it
- BleepingComputer: CISA orders feds to patch exploited Citrix flaws by Wednesday Read it
- Help Net Security: Authorizer: Open-source authentication and authorization for your apps Read it
- The Register: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought Read it
- Help Net Security: AI tests the limits of enterprise security governance Read it
- Help Net Security: Product showcase: A photo can fool your eyes. Verdict checks the evidence Read it
- Help Net Security: Quantum random numbers can pass the tests and still leak clues to attackers Read it
- BleepingComputer: OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email Read it
- CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway Read it
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
- BleepingComputer: Citrix admins warned to shut down NetScalers over 2 exploited zero-days Read it
Sources
- OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email BleepingComputer
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway CISA
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks SecurityWeek
- Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents Help Net Security
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation The Hacker News
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days BleepingComputer
- Cloudflare fixes Containers cross-tenant flaw exposing customer data BleepingComputer
- Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors BleepingComputer
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks BleepingComputer
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials The Hacker News
- China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks SecurityWeek
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings