Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now
CISA's Known Exploited Vulnerabilities catalog added Citrix NetScaler and Apple macOS flaws confirmed under attack, while Warlock ransomware kept exploiting SharePoint against utilities and telecoms.
Start with the vulnerabilities that attackers are already using. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 in Citrix NetScaler ADC as known to be exploited. The flaw carries a CVSS base score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — reachable over the network, no authentication and no user interaction required. CISA also lists CVE-2026-88772 in the same product as exploited; it scores 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Citrix's advisory names the fixed release as 13.1-64.23 for the 13.1 branch. Citrix's security bulletin (CTX697096) covers both. Move NetScaler ADC to 13.1-64.23 per the vendor advisory.
CISA's catalog also lists CVE-2026-86950 in Apple macOS as exploited, scoring 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), with user interaction required. Apple's advisory gives the fix in macOS 15.8.1. Apply it.
Google's Chrome release note addresses three flaws — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 — each scoring 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), fixed in Chrome 154.0.8037.92. These are not on CISA's KEV list. Update to 154.0.8037.92.
On active campaigns: The Hacker News reported that the suspected China-linked actor Warlock continues to weaponize Microsoft SharePoint vulnerabilities against organizations in Portuguese- and Spanish-speaking countries, observed by the Symantec and Carbon Black Threat Hunter Team, disabling security tools and deploying ransomware. BleepingComputer reported Warlock breached a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities to gain initial access. Audit your SharePoint patch state and monitor for security-tool tampering.
SecurityWeek reported Fortra patched critical vulnerabilities in BoKS that could lead to authentication bypass, shell command execution and memory corruption. Patch per Fortra's guidance.
On breaches: BleepingComputer reported the Technical University of Denmark says hackers accessed its identity and access management system and downloaded a large amount of data belonging to up to 200,000 users. BleepingComputer also reported Frontline Education is notifying school districts of a breach after attackers exploited a third-party software vulnerability and stole employee data including Social Security numbers.
On law enforcement and espionage: BleepingComputer reported a suspected ShinyHunters member known as "Rey" has been detained in Jordan and is cooperating with the FBI. The Hacker News reported MI5 issued a Security Service Espionage Alert on September 30, 2026 warning that more than 100 academics helped China's Ministry of State Security gather intelligence. The Register reported that exploitation attempts against a vulnerability came from a China-hosted IP, according to a VulnCheck researcher.
Sources
- BleepingComputer — ShinyHunters hacker reportedly detained in Jordan, aiding FBI
- The Register — Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
- The Hacker News — MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
- SecurityWeek — doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
- The Record — Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
- The Hacker News — Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- BleepingComputer — Danish university DTU breach exposes data of up to 200,000 people
- SecurityWeek — Fortra Patches Critical Vulnerabilities in BoKS
- The Hacker News — The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
- BleepingComputer — Frontline Education breach exposes school district employee data
- BleepingComputer — Warlock ransomware breach SharePoint in water, telecom operator attacks