Overview
Description
Statistics
- 22 Posts
- 6 Interactions
Fediverse
Detalles del exploit de Citrix NetScaler CVE-2026-88772 revelan ruta de ejecución de shellcode sin autenticación
https://blog.elhacker.net/2026/09/detalles-del-exploit-de-citrix.html
"Hackers exploit Citrix NetScaler zero-day to deploy web shells"
"[...] Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks."
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
Two Citrix NetScaler zero-days (CVE-2026-88772/88771) gave attackers pre-auth root on the box that fronts your whole network. GTIG traced exploitation to early September, weeks before the patch existed.
Once inside, their C2 leaves from your own public IP. No strange domain, no foreign address to block. The call is coming from inside the house.
Reputation Radar #13:
https://www.reput.io/blog/reputation-radar-13
Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow
Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisoryhttps://thecybersecguru.com/news/citrix-netscaler-cve-2026-88772-rce/
📰 Citrix Zero-Days and Oracle PeopleSoft Flaw Under Active Exploit
🚨 CRITICAL THREAT: Two Citrix zero-days (CVE-2026-88771, CVE-2026-88772) and an Oracle PeopleSoft flaw (CVE-2026-35273) are under active exploitation for RCE. CISA KEV updated. Patch immediately! #CyberSecurity #ZeroDay #CVE #PatchNow
Bluesky
Overview
Description
Statistics
- 9 Posts
- 2 Interactions
Fediverse
Apple a corrigé une faille CoreGraphics exploitée pour cibler des utilisateurs d’iPhone (CVE-2026-86950) https://www.it-connect.fr/apple-cve-2026-86950-faille-zero-day-coregraphics/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Apple
Apple released the urgent iOS 26.7.1 update to patch a critical zero-day vulnerability (CVE-2026-86950) in CoreGraphics, preventing arbitrary code execution.
Apple squashes zero-day bug exploited in ”extremely sophisticated” attack (CVE-2026-86950) – Help Net Security https://www.macken.xyz/2026/09/apple-squashes-zero-day-bug-exploited-in-extremely-sophisticated-attack-cve-2026-86950-help-net-security/?utm_source=dlvr.it&utm_medium=mastodon
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
#infosec
https://isc.sans.edu/diary/rss/33376
Bluesky
Overview
Description
Statistics
- 7 Posts
- 15 Interactions
Fediverse
Well would you look at that; it's Cisco 0-day o'clock again.
https://ifin.network/t/cve-2026-76504-cisco-sd-wan-auth-bypass-actively-exploited/874
🚨 Cisco warns critical SD-WAN Manager zero-day is actively exploited
CVE-2026-76504 is a critical authentication bypass affecting Cisco Catalyst SD-WAN Manager.
The flaw allows an unauthenticated remote attacker to send a crafted HTTP request that bypasses an API authentication rule and grants access with admin privileges.
⠀
The vulnerability carries a CVSS score of 9.8 and affects the product regardless of its configuration.
Cisco became aware of active exploitation in September after investigating a support case.
⠀
There are no workarounds. Administrators should install a fixed release immediately and investigate internet-facing systems for signs of compromise.
Attackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patch now.
#Cisco #SDWAN #CVE202676504 #AuthenticationBypass #ActivelyExploited #CyberSecurity
Bluesky
Overview
Description
Statistics
- 15 Posts
- 9 Interactions
Fediverse
An adversary tried Citrix NetScaler CVE-2026-88771 against a GreyNoise Swarm participant sensor more than three days before public disclosure, and GreyNoise labeled it malicious within seconds, before any CVE-specific detection existed. New sources followed within a day.
Elsewhere, sources checked F5 BIG-IP for a newly listed KEV flaw in the week CISA set a three-day federal deadline, and adversaries attempted two CrushFTP flaws in back-to-back single-day bursts. Next.js bypass sources ran at least four times their late August daily level on a flaw outside KEV. Build the control on the request behavior.
Customers get the full weekly brief. Our public At The Edge one-pager is attached + https://greynoise.io/resources/at-the-edge-clear-092826
CERT-EU shares their insights on CVE-2026-88771 exploitation and provides threat hunting tips in different logs.
https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow
Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler Gateway exploit, Citrix security advisoryhttps://thecybersecguru.com/news/citrix-netscaler-cve-2026-88772-rce/
📰 Citrix Zero-Days and Oracle PeopleSoft Flaw Under Active Exploit
🚨 CRITICAL THREAT: Two Citrix zero-days (CVE-2026-88771, CVE-2026-88772) and an Oracle PeopleSoft flaw (CVE-2026-35273) are under active exploitation for RCE. CISA KEV updated. Patch immediately! #CyberSecurity #ZeroDay #CVE #PatchNow
Bluesky
Overview
- WatchGuard
- Fireware OS
Description
Statistics
- 7 Posts
- 1 Interaction
Fediverse
Another one from Watch Guard.
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
CVE-2026-86131: CRITICAL code injection in WatchGuard Fireware OS BOVPN Over TLS. Attackers controlling a VPN server can execute root commands on Firebox devices. Avoid untrusted VPNs until patched. https://radar.offseq.com/threat/a-code-injection-vulnerability-in-watchguard-fireware-oss-bovpn-over-tls-client-configuration-handling-678dbd9b2069781f #OffSeq #WatchGuard #FirewareOS #Vuln
WatchGuard patched 14 Fireware OS vulnerabilities, including CVSS 9.2 RCE flaw CVE-2026-86131 in BOVPN Over TLS. Update Firebox appliances now.
#WatchGuard #FirewareOS #Firebox #CVE202686131 #FirewallSecurity #VPN #NetworkSecurity #PatchNow
CRITICAL RCE (CVE-2026-86131) in WatchGuard Fireware OS enables root code execution via BOVPN over TLS. Multiple high-severity flaws also patched. No known in-the-wild attacks, but update ASAP. https://radar.offseq.com/threat/watchguard-patches-critical-fireware-os-code-injection-vulnerability-36035f2a6c97cfc4 #OffSeq #Vuln #WatchGuard #PatchTuesday #InfoSec
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
Bluesky
Overview
Description
Statistics
- 4 Posts
- 6 Interactions
Fediverse
Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.
#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity
https://securityonline.info/zimbra-cve-2026-73570-2/?utm_source=mastodon&utm_medium=jetpack_social
Bluesky
Overview
- TeamViewer
- Full Client
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
Update to 15.82 now. Five high-severity TeamViewer vulnerabilities include CVE-2026-92370, CVE-2026-19743 and CVE-2026-92368 in Full Client and Host.
#TeamViewer #RemoteAccess #CVE202692370 #PrivilegeEscalation #Windows #Linux #macOS #PatchNow
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
WordPress spent ten years letting strangers include arbitrary PHP. The patch dropped, exploits followed hours later. Update the server you forgot exists.
https://www.kaspersky.com/blog/cve-2026-87902-wordpress-vulnerability/56459/
Overview
- Wikimedia Foundation
- Mediawiki - ExternalData Extension
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
[🚨 #MediaWiki vulnerable extension]
If you are running a MediaWiki instance with Extension:External_Data < v3.7, your instance is vulnerable to arbitrary file loading and #RemoteCodeExecution.
The vulnerability was apparently publicly known since August, but due to the lack of communication, instance admins learned about it due to that vulnerability being exploited en masse.
If you know and like a MediaWiki instance, you can check their Special:Version page to see if they are using the External_Data extension to warn them.
More info:
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-l@lists.wikimedia.org/thread/5N55R3XNFE7BXQLGWKZI7Q4ZXZSF4C5I/
- https://www.cve.org/CVERecord?id=CVE-2026-100382
#infosec #wikipedia #wikidata #adminsys #CVE #pwned cc @mediawiki