ITsecurity Daily
Daily Briefing
Citrix patches an actively exploited NetScaler zero-day; CISA orders federal remediation
Good morning. BleepingComputer reported that Citrix released emergency updates for a new NetScaler denial-of-service vulnerability that has been exploited in zero-day attacks, and that researchers are investigating whether it can also be exploited for remote code execution. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 4 October, based on evidence of active exploitation, and described it as a Citrix NetScaler "Improper Restriction of Operations within the Bounds of a Memory Buffer" vulnerability.
What to do: CISA states that Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of vulnerabilities in the KEV catalog. BleepingComputer reported that Citrix has released emergency updates; apply them to any NetScaler you run, prioritising internet-facing appliances. Match your estate against what Citrix lists as affected, and treat this as under active attack rather than a routine patch.
In extortion-group news, The Hacker News and BleepingComputer both reported that a suspected member of the ShinyHunters group, known online as "Rey," has been detained in Jordan and is cooperating with the FBI to identify other members. The Hacker News reported, citing Reuters, that Rey's real name is Saif al-Din Khader and that he was brought into custody on 29 September.
Zoom out: Help Net Security's week in review listed the NetScaler zero-day among last week's most significant security news.
Vulnerability in focus
CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- Help Net Security: Three questions a hospital CISO should ask a healthcare fintech vendor Read it
- SecurityWeek: Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier Read it
- Help Net Security: How RMM abuse gives attackers a way in that looks like business as usual Read it
- BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks Read it
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog Read it
- Help Net Security: Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited Read it
- The Hacker News: ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members Read it
Sources
- Citrix patches NetScaler SAML zero-day exploited in attacks BleepingComputer
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited Help Net Security
- ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members The Hacker News
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing The Hacker News
- ShinyHunters hacker reportedly detained in Jordan, aiding FBI BleepingComputer
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings