ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now
IT SECURITY DESK

Three actively exploited flaws land on CISA's KEV list — Citrix, Apple patch now

CISA's Known Exploited Vulnerabilities catalog added Citrix NetScaler and Apple macOS flaws confirmed under attack, while Warlock ransomware kept exploiting SharePoint against utilities and telecoms.

Start with the vulnerabilities that attackers are already using. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-88771 in Citrix NetScaler ADC as known to be exploited. The flaw carries a CVSS base score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) — reachable over the network, no authentication and no user interaction required. CISA also lists CVE-2026-88772 in the same product as exploited; it scores 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Citrix's advisory names the fixed release as 13.1-64.23 for the 13.1 branch. Citrix's security bulletin (CTX697096) covers both. Move NetScaler ADC to 13.1-64.23 per the vendor advisory.

CISA's catalog also lists CVE-2026-86950 in Apple macOS as exploited, scoring 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), with user interaction required. Apple's advisory gives the fix in macOS 15.8.1. Apply it.

Google's Chrome release note addresses three flaws — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 — each scoring 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), fixed in Chrome 154.0.8037.92. These are not on CISA's KEV list. Update to 154.0.8037.92.

On active campaigns: The Hacker News reported that the suspected China-linked actor Warlock continues to weaponize Microsoft SharePoint vulnerabilities against organizations in Portuguese- and Spanish-speaking countries, observed by the Symantec and Carbon Black Threat Hunter Team, disabling security tools and deploying ransomware. BleepingComputer reported Warlock breached a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities to gain initial access. Audit your SharePoint patch state and monitor for security-tool tampering.

SecurityWeek reported Fortra patched critical vulnerabilities in BoKS that could lead to authentication bypass, shell command execution and memory corruption. Patch per Fortra's guidance.

On breaches: BleepingComputer reported the Technical University of Denmark says hackers accessed its identity and access management system and downloaded a large amount of data belonging to up to 200,000 users. BleepingComputer also reported Frontline Education is notifying school districts of a breach after attackers exploited a third-party software vulnerability and stole employee data including Social Security numbers.

On law enforcement and espionage: BleepingComputer reported a suspected ShinyHunters member known as "Rey" has been detained in Jordan and is cooperating with the FBI. The Hacker News reported MI5 issued a Security Service Espionage Alert on September 30, 2026 warning that more than 100 academics helped China's Ministry of State Security gather intelligence. The Register reported that exploitation attempts against a vulnerability came from a China-hosted IP, according to a VulnCheck researcher.

Related