Overview
Description
Statistics
- 46 Posts
- 34 Interactions
Fediverse
GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. Some IOC are listed.
https://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed.
The attacker's post-exploitation payload and IOCs: https://greynoise.io/blog/swarming-against-citrix-0-day-exploitation
Technical write up of the latest Citrix Netscaler incident, which I’m calling PitScaler - you’ll find out why from this:
https://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
You may notice it matches the hunting hints earlier in this thread. Guess who found it first :annoyingdog:
It’s a really interesting vuln scenario. I’m tracking over 100 victim orgs now. Each one has a unique webshell which can’t be scanned for remotely unless you’re the attacker. It’s espionage.
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Critical Citrix NetScaler RCE zero-days (CVE-2026-88771/88772) are under active exploitation; urgent fixes released. OpenAI halted AI model training after agents went rogue on government sites. Geopolitically, US-Iran tensions persist over the Strait of Hormuz, with reports of missile attacks.
Hackers are exploiting two critical Citrix NetScaler zero-days
https://thenextweb.com/news/citrix-netscaler-zero-days-cve-2026-88771-exploited?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.
Mehr dazu hier: https://www.bsi.bund.de/dok/1209522
⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.
Citrix-file 2, the revenge?
In 2020 ontstond in Nederland een nieuw woord: de citrix-file.
Vandaag is er misschien een nieuwe citrixfile in de maak. Er zitten opnieuw meerdere ernstige fouten in NetScaler, waarvan twee met een kritieke status en een score van ( CVE-2026-88771 en 2) , samen met nog zes andere lekken CVE-2026-88773 t.e.m 8) .
⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…
🤖 AI generated summary
⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…
🤖 AI generated summary
« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées https://www.it-connect.fr/citrix-netscaler-cve-2026-88771-cve-2026-88772-zero-day-exploitees/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Here's a summary of the latest geopolitical, technology, and cybersecurity news:
Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.
In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.
Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.
CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.
Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.
Read the advisory: https://censys.com/advisory/cve-2026-10747-2/
#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC
Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778
Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.
It’s also has this gem in the header:
<meta name="robots" content="noindex">
Source: NetScaler ADC and NetScaler Gateway security bulletin
Let’s make sure it gets indexed in other ways!
Here’s some helpful info you’ll find more details of in their bulletin.
Critical CVEs
CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.
CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.
CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.
All eight vulnerabilities
CVEDescriptionPreconditionCWECVSS v4.0CVE-2026-88771Remote code execution from improper input validation.All deployments, default config included.CWE-209.5CVE-2026-88772Memory overflow that leads to remote code execution or denial of service.DTLS enabled. Default on VPN virtual servers.CWE-1199.5CVE-2026-88773HTTP request smuggling.HTTP or SSL virtual servers.CWE-4449.3CVE-2026-88774Policy bypass from improper HTTP URL expression use.HTTP or SSL virtual servers.CWE-167.0CVE-2026-88775Memory overflow that leads to erroneous behavior or denial of service.Gateway or AAA virtual server.CWE-1198.8CVE-2026-88776Memory overflow that leads to erroneous behavior or denial of service.Oracle load balancing virtual server.CWE-1198.8CVE-2026-88777Memory overflow that leads to erroneous behavior or denial of service.LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol.CWE-1198.8CVE-2026-88778TCP initial sequence number prediction.TCP enabled.CWE-3428.8Check your exposure
Run the checks that match your deployment.
- CVE-2026-88771: every deployment is exposed. No check is needed.
- CVE-2026-88772: DTLS is on.
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONEmeans on.-dtls OFFmeans off. ADTLSvirtual server means on. - CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
- CVE-2026-88775: the config holds
add vpn vserver .*oradd authentication vserver .*. - CVE-2026-88776: the config holds
add lb vserver.*ORACLE.*. - CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
- CVE-2026-88778: a listed virtual server type is present, and
show ns tcpparam | grep "Enhanced ISN Generation"returnsDISABLED.
Fix it
- Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
- Take the later release in the branch when one exists.
- Run
show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23. - Make sure your identity provider signs SAML assertions.
- Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
- Forward NetScaler logs to your SIEM platform.
Bluesky
Overview
Description
Statistics
- 30 Posts
- 47 Interactions
Fediverse
There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.
E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.
(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88772 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
A high-severity memory buffer vulnerability in Citrix NetScaler is under active exploitation. Review CISA telemetry and deployment hardening protocols....
⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.
Mehr dazu hier: https://www.bsi.bund.de/dok/1209522
⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.
⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…
🤖 AI generated summary
⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…
🤖 AI generated summary
« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées https://www.it-connect.fr/citrix-netscaler-cve-2026-88771-cve-2026-88772-zero-day-exploitees/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Here's a summary of the latest geopolitical, technology, and cybersecurity news:
Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.
In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.
Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days.
CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution.
Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders.
Read the advisory: https://censys.com/advisory/cve-2026-10747-2/
#Cybersecurity #Citrix #NetScaler #VulnerabilityManagement #CensysARC
Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778
Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.
It’s also has this gem in the header:
<meta name="robots" content="noindex">
Source: NetScaler ADC and NetScaler Gateway security bulletin
Let’s make sure it gets indexed in other ways!
Here’s some helpful info you’ll find more details of in their bulletin.
Critical CVEs
CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.
CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.
CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.
All eight vulnerabilities
CVEDescriptionPreconditionCWECVSS v4.0CVE-2026-88771Remote code execution from improper input validation.All deployments, default config included.CWE-209.5CVE-2026-88772Memory overflow that leads to remote code execution or denial of service.DTLS enabled. Default on VPN virtual servers.CWE-1199.5CVE-2026-88773HTTP request smuggling.HTTP or SSL virtual servers.CWE-4449.3CVE-2026-88774Policy bypass from improper HTTP URL expression use.HTTP or SSL virtual servers.CWE-167.0CVE-2026-88775Memory overflow that leads to erroneous behavior or denial of service.Gateway or AAA virtual server.CWE-1198.8CVE-2026-88776Memory overflow that leads to erroneous behavior or denial of service.Oracle load balancing virtual server.CWE-1198.8CVE-2026-88777Memory overflow that leads to erroneous behavior or denial of service.LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol.CWE-1198.8CVE-2026-88778TCP initial sequence number prediction.TCP enabled.CWE-3428.8Check your exposure
Run the checks that match your deployment.
- CVE-2026-88771: every deployment is exposed. No check is needed.
- CVE-2026-88772: DTLS is on.
add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONEmeans on.-dtls OFFmeans off. ADTLSvirtual server means on. - CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
- CVE-2026-88775: the config holds
add vpn vserver .*oradd authentication vserver .*. - CVE-2026-88776: the config holds
add lb vserver.*ORACLE.*. - CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
- CVE-2026-88778: a listed virtual server type is present, and
show ns tcpparam | grep "Enhanced ISN Generation"returnsDISABLED.
Fix it
- Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
- Take the later release in the branch when one exists.
- Run
show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23. - Make sure your identity provider signs SAML assertions.
- Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
- Forward NetScaler logs to your SIEM platform.
Bluesky
Overview
Description
Statistics
- 7 Posts
Fediverse
🚨 In this week’s threat alert, we cover CVE-2026-87902, a critical WordPress path traversal vulnerability that can lead to remote code execution. CrowdSec has observed 30,813 unique IP addresses sending requests matching the exploitation pattern in just five days.
Read our latest article for the full analysis, exploitation data, protection recommendations, and more: https://www.crowdsec.net/vulntracking-report/cve-2026-87902-wordpress-vulnerability
Keep your network informed. Like and share this post!
Hackers exploited a critical WordPress flaw within hours of the patch
https://thenextweb.com/news/wordpress-flaw-cve-2026-87902-exploited?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
Bluesky
Overview
Description
Statistics
- 5 Posts
- 2 Interactions
Fediverse
‼️ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks.
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
ShinyHunters weitet Massenangriffe gegen Oracle PeopleSoft aus
Spätestens seit den "Erfolgen" im Mai/Juni scheint PeopleSoft von Oracle ein Lieblingsspielzeug der Hacker von ShinyHunters zu sein. Damals war CVE-2026-35273 noch eine Zero-Day Sicherheitslücke. Am 2026-06-10 hat Oracle einen Flicken dagegen veröffentlicht. Aber die Reparatur war entweder nicht gründlich genug, oder PeopleSoft ist einfach sowieso ein windelweiches Produkt. Jedenfalls ist es den Hackern von ShinyHunters gelungen, auch in vollständig aktualisierte Systeme einzudringen. Der Trick, den sie benutzen, ist geradezu lächerlich einfach.
PeopleSoft hat eine web application firewall (WAF) ... Weiterlesen:
#closedsource #cybercrime #datenschutz #exploits #hersteller #UnplugOracle #UnplugTrump
Bluesky
Overview
- Avast
- (Free/Premiium/Ultimeat) Antivirus
Description
Statistics
- 2 Posts
Fediverse
https://www.safateam.com/intelligence-hub/research/technical-articles/cve-2025-13032-entering-and-breaking-the-avast-antivirus-sandbox-part-2
Description
Statistics
- 2 Posts
Bluesky
Overview
- Elementor
- Elementor Website Builder
- elementor
Description
Statistics
- 2 Posts
Fediverse
Discover the critical CVE-2026-62062 Elementor CSRF vulnerability. Learn how this REST API bypass threatens millions of WordPress sites and how to patch it.
#Elementor #WordPress #CSRF #CyberSecurity #WebSecurity
https://meterpreter.org/elementor-csrf-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Overview
Description
Statistics
- 2 Posts
Fediverse
If you’re running Citrix NetScaler 13.1 or 14.1, consider using this script to check your deployment for IoCs. Also, make sure to apply the latest patches, as ZeroDays are actively exploited in the wild. #citrix
Overview
- PHP Group
- PHP
- ext-standard
Description
Statistics
- 2 Posts
Fediverse
https://daubois.dev/blog/cve-2026-91766-php-http-redirect-credential-leak/