Citrix NetScaler flaw is being exploited now; Chrome ships five critical fixes
CISA added an actively-exploited Citrix NetScaler ADC bug to its Known Exploited Vulnerabilities catalog, Google patched five critical Chrome flaws, and researchers exploited 32 zero-days on day one of Pwn2Own Ireland.
Patch Citrix first. CISA lists CVE-2026-88779 on its Known Exploited Vulnerabilities catalog and records it as known to be exploited. Citrix's advisory covers NetScaler ADC 13.1 up to the fix in 13.1-37.282; the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H carries a base score of 7.5, an availability-only impact reachable over the network with no authentication or user interaction. CISA directs stakeholders to apply mitigations in line with the vendor advisory and BOD 26-04, or discontinue use if no mitigation is available.
Google patched five critical Chrome flaws, each scored CVSS 9.6 against the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H: CVE-2026-106419, CVE-2026-106417, CVE-2026-106414, CVE-2026-106401 and CVE-2026-106382. Google's advisory lists the fix in Chrome 155.0.8059.39. None is on CISA's KEV catalog. Update the browser and confirm the build.
Exploitation in the wild, by outlet. BleepingComputer reported hackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue admin accounts. BleepingComputer also reported Atlassian is warning of a critical arbitrary file-access flaw in self-hosted Data Center products including Confluence, Jira and Bitbucket. And BleepingComputer reported that on day one of Pwn2Own Ireland 2026 researchers exploited 32 zero-days, hacking the Samsung Galaxy S26 twice and earning $388,500.
Breaches and campaigns. BleepingComputer reported ASOS confirmed a data breach after attackers sent unauthorized push notifications through its app and claimed to have stolen customer data from its Snowflake environment. SecurityWeek reported the FBI removed an Accenture contractor over a breach it blames on a missed patch, which exposed personal data of thousands of bureau employees. The Record reported South Korean officials believe AI agents and a Chinese cybersecurity tool were used to breach at least seven financial institutions, exposing data on at least 68,000 people. BleepingComputer and The Hacker News reported a human-operated phishing platform using fake ChatGPT, Gemini, Claude and Perplexity ad portals to steal credentials and MFA codes via browser-in-browser attacks.
Also note: CISA published an advisory for Hitachi Energy RTU500 end-of-life CMU firmware 9.x, from findings reported by Dragos; and Schneier on Security, citing 404Media, reports a cyber-weapons manufacturer is exploiting an iOS flaw to bypass the automatic reboot that secures an idle iPhone after 72 hours.
Sources
- The Register — Anthropic reconfigures its cool kids security program
- BleepingComputer — Ninja Forms plugin flaw exploited to hack WordPress sites
- The Hacker News — Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
- The Record — Alleged ATM malware creator appears in Nebraska court after arrest
- SecurityWeek — FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
- Help Net Security — Anaconda combines agent swarms with autonomous security testing
- CISA — Hitachi Energy RTU500
- Schneier on Security — Possible Vulnerability in Apple’s Automatic Reboot
- BleepingComputer — Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
- The Hacker News — Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
- BleepingComputer — Atlassian warns of critical file-access flaw in Jira, Confluence
- BleepingComputer — ASOS confirms data breach after “HACKED” in-app notifications
- The Record — South Korean officials believe AI agents were used to hack several banks
- BleepingComputer — Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes