ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Tuesday, 29 September 2026: Citrix NetScaler exploitation goes from stealth to mass attacks; Apple flaw added to KEV

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Citrix NetScaler exploitation goes from stealth to mass attacks; Apple flaw added to KEV

Good morning. Help Net Security reported that exploitation of internet-exposed Citrix NetScaler ADC and Gateway deployments has escalated from stealthy zero-day targeting into widespread "spray and pray" exploitation of CVE-2026-88771, fueled by the publication of a root-cause analysis and a proof-of-concept exploit. CVE-2026-88771 carries the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a base score of 9.8, and CISA lists it as known to be exploited. The affected software is Citrix NetScaler ADC 13.1 up to the fix in 13.1-64.23.

BleepingComputer reported that attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. That CVE has the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 8.1, and is also on CISA's KEV list. The Register reported that the custom malware used in these Citrix zero-day attacks targeted government, banks, and professional services, and noted that two questions remain: who is abusing the CVEs, and why Citrix took so long to disclose. Citrix's security bulletin (CTX697096) covers this cluster of CVEs, which also includes CVE-2026-88777, CVE-2026-88776, and CVE-2026-88775 — each scored 9.8 but not currently on KEV. What to do: apply the fixed release 13.1-64.23 per Citrix's advisory, and treat exposed appliances as potentially compromised — hunt for web shells, unexpected root activity, and lateral movement given the credential theft BleepingComputer describes.

CISA announced it added CVE-2026-86950, an Apple Multiple Products Out-of-Bounds Write Vulnerability, to its KEV Catalog based on evidence of active exploitation. The advisory lists the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, a base score of 8.8, and macOS up to the fix in 15.8.1 as affected. Follow Apple's advisory for the fixed release; CISA's BOD 26-04 requires federal agencies to prioritize rapid remediation of KEV-listed flaws.

Read the full briefing →

Zoom out: CISA added an actively exploited Apple out-of-bounds write flaw to its Known Exploited Vulnerabilities Catalog, and Help Net Security reports Citrix NetScaler exploitation has escalated from stealthy targeting into mass "spray and pray."

Vulnerability in focus

CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.

Affected: macos.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • SecurityWeek: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Read it
  • The Hacker News: Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution Read it
  • Help Net Security: Security tools can now scan Claude Enterprise chats and uploads for sensitive data Read it
  • Help Net Security: EU Cyber Resilience Act requirements for containers and Kubernetes Read it
  • Help Net Security: In this new SME cybersecurity service, the AI assists and the consultants decide Read it
  • Help Net Security: Most open critical and high flaws are over 90 days old Read it
  • Help Net Security: Most organizations need six months or longer to roll out new security controls Read it
  • Help Net Security: Post-quantum website certificates from Cloudflare are scheduled for early 2027 Read it
  • The Register: Add one more AI worry to the nightmare scenario: self-replicating prompt injections Read it
  • The Record: US Air Force members given over 6 years in prison for cyber theft of more than $2 million Read it
  • The Record: Controversial spyware firm Paragon to go public by end of year Read it
  • SecurityWeek: OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email