Overview
Description
Statistics
- 21 Posts
- 40 Interactions
Fediverse
CISA adds CVE-2026-88779 to the KEV Catalog. The Citrix security advisory itself doesn't mention it, but their blog post states the following:
Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.
Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24 hours:
Geopolitically, Russia launched 205 drones at Ukraine, with three hitting Kharkiv on October 5, killing one and injuring eight. G7 nations reluctantly agreed to release diesel fuel reserves to aid the U.S. on October 4. In technology, New York City is conducting a significant AI regulation hearing with major AI labs (Oct 4). Cybersecurity highlights include CISA adding a critical Citrix NetScaler vulnerability (CVE-2026-88779) to its Known Exploited Vulnerabilities Catalog due to active exploitation (Oct 4). Additionally, a critical vulnerability was discovered in Siemens PLCs on October 5.
🚨 Citrix discloses high-severity NetScaler flaw tracked as CVE-2026-88779
⠀
CVE-2026-88779 is a memory overflow vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments. Successful exploitation can cause a denial-of-service condition. Citrix assigned it a CVSS v4.0 score of 8.7.
⠀
The vulnerability applies when the appliance is configured as either:
⠀
• A SAML Service Provider (SP)
• A SAML Identity Provider (IdP)
⠀
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with affected FIPS and NDcPP builds. Citrix is urging customers to install the updated releases as soon as possible.
⠀
CVE: CVE-2026-88779
Severity: High
CVSS v4.0: 8.7
Impact: Denial of Service
CWE: CWE-119
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for CVE-2026-88779, a high-severity (CVSS 8.7) memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that has been exploited in targeted zero-day attacks. Successful exploitation can knock SAML-based deployments offline. Citrix urges administrators to apply the updates immediately. https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html
TheCyberMind.co™ Survival Series —Part 4
CISA added CVE-2026-88779 affecting Citrix NetScaler ADC and Gateway to the KEV catalog. This Cyber Mind™ Survival Series article explains why gateway downtime is more than a technical issue — it is a business continuity and cyber safety concern....
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog - Security Affairs
📰 Citrix Patches Critical NetScaler Zero-Day Under Active Attack
Citrix patches critical zero-day (CVE-2026-88779) in NetScaler ADC & Gateway under active attack. The flaw can cause DoS & potential RCE. CISA added it to its KEV catalog, mandating federal agencies to patch by Oct 7. #NetScaler #ZeroDay #CVE
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes executive risk analysis, CISO compliance steps, and comprehensive asset hardening runbooks....
Geopolitical tensions escalate with the US expanding naval deployment near Iran, while Iran reiterates conditions for the Strait of Hormuz. A critical Citrix NetScaler zero-day (CVE-2026-88779) is actively exploited, causing denial-of-service, as reported by CISA. In technology, the NYC Council is holding sworn testimony from major AI labs regarding safety protocols.
I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. https://www.deyda.net/index.php/de/2026/08/28/netscaler-cve-checkliste-updates-sicherheitspruefung-und-incident-response/
The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.
Bluesky
Overview
Description
Statistics
- 9 Posts
- 1 Interaction
Fediverse
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical Rejetto HTTP File Server flaw (CVE-2026-61500, CVSS 9.3) is seeing active exploitation attempts, according to VulnCheck. The session-forgery bug stems from a weak pseudo-random number generator producing predictable keys, letting attackers gain unauthorized access and potentially achieve remote code execution. https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
CVE-2026-61500 enables attackers to recover the session-cookie signing key, obtain administrative access and execute code remotely on Rejetto HFS.
Source: SecurityWeek
https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
📰 Attackers Actively Exploit Critical RCE Flaw in Rejetto HFS
Critical RCE flaw in Rejetto HFS (CVE-2026-61500, CVSS 9.3) is under active attack. A weak RNG allows attackers to forge admin cookies. A Chinese threat actor is targeting US servers. Patch to HFS version 3.2.1 now! #RCE #Vulnerability #CyberAttack
Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It. - Security Affairs
Bluesky
Overview
- defunkt
- gist
Description
Statistics
- 2 Posts
- 54 Interactions
Fediverse
WTF?
https://nvd.nist.gov/vuln/detail/cve-2026-105221
sev:CRIT 9.1 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! https://radar.offseq.com/threat/cve-2026-105221-improper-certificate-validation-in-defunkt-gist-a4b1b7125f9195f8 #OffSeq #CVE2026105221 #RubyGems #infosec
Overview
- MikroTik
- RouterOS
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated remote code execution vulnerability affecting MikroTik RouterOS web management.
Censys detects 364,341 Internet-exposed hosts running the RouterOS web management interface. Roughly 19,200 report RouterOS 7.x, and none currently report the patched 7.24 release or later.
The broader exposure count does not represent confirmed-vulnerable devices because the impact to RouterOS 6.x has not yet been established. No public exploitation has been reported.
Full Censys ARC advisory: https://censys.com/advisory/cve-2026-84411/
Bluesky
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.
Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html
Bluesky
Overview
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
The Internet Last Week
* Android developer verification deployment
https://developer.android.com/developer-verification
https://android-developers.googleblog.com/2025/08/elevating-android-security.html
* Apple emergency patches for CVE-2026-86950
https://isc.sans.edu/diary/Apple+Emergency+Patch+for+iOS+26+macOS26+macOS15+CVE202686950/33376/
* Microsoft Azure services connectivity issue
https://azure.status.microsoft/status/history/?trackingId=7Q30-010
* Ukraine Internet outages
https://infosec.exchange/@dougmadory/117350575089846672
https://mastodon.social/@netblocks/117345521691338107
https://mastodon.social/@netblocks/117343895159569005
Meta caught someone burning a zero-day on Apple's graphics parser. Update your pocket glass so state surveillance has to spend another million dollars next week.
https://betanews.com/article/apple-patches-coregraphics-flaw-cve-2026-86950/
Overview
- Progress Software
- @progress/sitefinity-nextjs-sdk
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳
https://www.cve.org/CVERecord?id=CVE-2026-92931
sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
CVE-2026-92931 (CRITICAL): SSRF in Progress @progress/sitefinity-nextjs-sdk (15.1.8326 – 15.4.8637). Remote attackers may access internal resources. Monitor for patches & restrict egress where possible. https://radar.offseq.com/threat/cve-2026-92931-cwe-918-server-side-request-forgery-in-progress-software-progresssitefinity-nextjs-sdk-6c11605d160820a3 #OffSeq #CVE #SSRF #Vuln
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 2 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 3 Posts