ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Citrix NetScaler zero-days under active exploitation top a heavy day for defenders
IT SECURITY DESK

Citrix NetScaler zero-days under active exploitation top a heavy day for defenders

CISA amplified Citrix's disclosure of eight NetScaler flaws and added two to its exploited-vulnerabilities catalogue as an exploited SharePoint bug reached its patch deadline and ShinyHunters resumed PeopleSoft attacks.

CISA said it is amplifying Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 and CVE-2026-88778. In a separate alert CISA added two of them to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation: CVE-2026-88771, which CISA describes as an improper input validation vulnerability, and CVE-2026-88772, which CISA describes as an improper restriction of operations within the bounds of a memory buffer.

The Hacker News reported that security firm watchTowr said on September 26 that two unpatched NetScaler zero-days allowing remote code execution are being actively exploited in the wild, and that Citrix has not confirmed the flaws or published a fix. BleepingComputer reported that Citrix administrators are being warned to shut down NetScalers over the two exploited zero-days, with patches expected next week. If you run NetScaler ADC or Gateway, match your appliances against the CVEs above; BleepingComputer's guidance to take appliances offline until a fix ships is the mitigation on record while no patch exists.

SecurityWeek reported that CISA added Microsoft SharePoint flaw CVE-2026-65660 to its KEV catalogue, now exploited in attacks, with a federal patching deadline of September 28. Treat that deadline as the clock for SharePoint operators.

BleepingComputer reported that the ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate Oracle PeopleSoft CVE-2026-35273, letting the group resume widespread exploitation. WAF-based mitigation alone is being defeated; treat the underlying flaw as the fix point.

BleepingComputer reported that Cloudflare fixed a vulnerability in Containers and Sandboxes that let customers with a Workers Paid account recover residual data from other customers' containers on the same physical host.

The Hacker News reported, citing Ontinue, that Lunex Stealer abuses an AMD driver to disable security monitoring and steal browser credentials, distributed as Psychedelic Stealer via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks in a four-stage chain targeting Ukraine.

In its week-in-review, Help Net Security reported that a Gyazo breach exposed 23.6 million users' data and that TASK#STOMP steals documents. Elsewhere, BleepingComputer reported OpenAI is testing an always-on assistant called "o" and that Anthropic announced a Claude Marketplace with more than 2,000 plugins and connectors, and SecurityWeek reported the US and China agreed to set up a communication mechanism for AI-related incidents.

Related