24h | 7d | 30d

Overview

  • NetScaler
  • ADC

04 Oct 2026
Published
04 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.28%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Statistics

  • 8 Posts
  • 93 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because

(CVE-2026-88779 advisory and patch included now)

ifin.network/t/multiple-citrix

  • 13
  • 22
  • 0
  • 16h ago
Profile picture fallback

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

  • 21
  • 35
  • 0
  • 11h ago
Profile picture fallback

Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now.

securityonline.info/citrix-net

  • 1
  • 1
  • 0
  • 12h ago
Profile picture fallback

CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway <14.1-73.41, <13.1-64.28, <13.1-37.282. Remote, unauthenticated attackers can disrupt availability. Patch required; no active exploits. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

Einordnung: NetScaler-Zero-Day trifft Fernwartung

Citrix NetScaler: Zero-Day CVE-2026-88779 wird ausgenutzt. Wer SAML nutzt, sollte sofort auf 14.1-73.41 bzw. 13.1-64.28 patchen – auch die Fernwartung.


ot-cyber.de/blog/einordnung-ne

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

#Citrix die #Schwachstelle #CVE-2026-88779 im NetScaler ADC und NetScaler Gateway bestätigt. Führt zum Absturz, kann für Denial of Service-Angriffe missbraucht werden. Also patchen.

borncity.com/blog/2026/10/04/c

  • 0
  • 0
  • 1
  • 1h ago

Bluesky

Profile picture fallback
~Cisa~ CISA reports active exploitation of a Citrix NetScaler memory-buffer vulnerability and urges rapid remediation. - IOCs: CVE-2026-88779 - #CVE-2026-88779 #Citrix #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Fortinet
  • FortiMail

01 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.20%

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

2026-W40 — Weekly Threat Roundup

🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.
🏴‍☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.
🇨🇳 China-linked Warlock…

threatnoir.com/weekly/2026-w40

🤖 AI generated summary

  • 1
  • 0
  • 0
  • 16h ago
Profile picture fallback

Another week; another Fortinet vulnerability.

Fortinet disclosed CVE-2026-104286 on Oct. 1 and confirmed active exploitation. Path-traversal lets unauthenticated attackers write arbitrary files, which can lead to command execution. Until fixes arrive, disable IBE or restrict the management interface to trusted networks. Preserve evidence and review Fortinet’s IoCs; mitigation does not erase a compromise.

fortiguard.com/psirt/FG-IR-26-

#Cybersecurity #FortiMail #VulnMgmt

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Geopolitical tensions are escalating with intensified fighting in Yemen, as Iran reiterates that there is "no military solution" to the ongoing conflict. In technology, OpenAI has halted the release of its GPT-6.1 Astra model citing safety concerns, highlighting the growing scrutiny of advanced AI. On the cybersecurity front, a suspected ShinyHunters hacker has been detained in Jordan, assisting the FBI. Urgent action is also advised for an exploited critical FortiMail zero-day vulnerability (CVE-2026-104286).

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) #patchmanagement
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
📢 ⚠️ [VULN] Utilisateurs de FortiMail, attention à une nouvelle vulnérabilité critique - CVE-2026-104286 Fortinet vient d’avertir d’une vulnérabilité critique de traversée de chemin dans FortiMail. Référencée CVE-2026-104286, elle est déjà exploitée par des acteurs… #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • GitLab
  • GitLab AI Gateway

02 Oct 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.94%

KEV

Description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

Statistics

  • 3 Posts
  • 4 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

POV: you shipped an AI gateway

the prompt template: "hi {{name}}"

a logged in user with a crafted flow config: "what if i was a shell"

gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0. fixed in 19.2.4, 19.3.2, 19.4.1. gitlab.com and dedicated already patched

#InfoSec #GitLab #AI #DevSecOps

  • 2
  • 2
  • 0
  • 11h ago
Profile picture fallback
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION - Security Affairs
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.06%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 3 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

I didn’t realize the EU CERT was so witty!

cert.europa.eu/blog/taking-exe

(analysis of the NetScaler thing from last week.)

  • 1
  • 3
  • 0
  • 2h ago

Bluesky

Profile picture fallback
netscaler-ctx697096-checker: Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): build, all 8 CVE preconditions, Enhanced ISN, upgrade risks, SAML status, plus --ioc sweep with every public IoC (webshells, implants, backdoor ad
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Cybergcca~ Actively exploited NetScaler flaws enable remote code execution and appliance compromise. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #CVE202688772 #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Zammad GmbH
  • Zammad

30 Sep 2026
Published
03 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
1.40%

Description

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Zammad security alert: session hijacking and remote code execution

CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.

Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.

#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

  • 2
  • 0
  • 0
  • 8h ago
Profile picture fallback

(CISA TwS) The Cyber Mind TSUITE Brief: CVE-2026-102489 – Zammad GmbH Zammad Session Fixation Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-102489 affecting Zammad. Includes session fixation RCE analysis, BOD 26-04 compliance guidance, and multi-vendor SOC detection queries....

thecybermind.co/l7ux

  • 0
  • 0
  • 1
  • 6h ago

Overview

  • NetScaler
  • ADC

25 Jun 2025
Published
26 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
10.56%

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Statistics

  • 1 Post
  • 56 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: support.citrix.com/support-hom

Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: doublepulsar.com/citrix-forgot

  • 21
  • 35
  • 0
  • 11h ago

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

30 Sep 2026
Published
02 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.58%

Description

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Discover how a single encoded character exploited a critical Cisco zero-day vulnerability in the Catalyst SD-WAN Manager, granting attackers admin access.

meterpreter.org/cisco-zero-day

  • 1
  • 2
  • 0
  • 13h ago

Overview

  • Legion of the Bouncy Castle Inc.
  • BC-JAVA
  • bcmls

03 Oct 2026
Published
03 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.19%

KEV

Description

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-71885 (CRITICAL): Bouncy Castle for Java <1.86 suffers from X.509 credential binding flaw in MLS. Attackers can impersonate users & decrypt group messages. Upgrade to v1.86+ now. radar.offseq.com/threat/in-bou

  • 1
  • 1
  • 0
  • 21h ago

Overview

  • vincent-peugnet
  • wcms

03 Oct 2026
Published
03 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.52%

KEV

Description

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

vincent-peugnet wcms ≤3.18.0 is vulnerable (CVE-2026-105123, HIGH, CVSS 8.7): Authenticated editors can upload malicious files via /api/v0/media/upload/ and delete arbitrary files. Restrict privileges, monitor uploads. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 19h ago

Overview

  • The Document Foundation
  • LibreOffice

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v4.0
MEDIUM (5.4)
EPSS
0.17%

KEV

Description

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the text walked the advance array by character position and ran past its end when the array was the shorter of the two. In fixed versions an advance array shorter than its text is ignored.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-63272 LibreOffice heap buffer overflow when importing WMF graphics in documents. CVSS 5.3. No patch yet. Avoid untrusted files and update as soon as a fix ships. valtersit.com/cve/CVE-2026-632 #CVE #infosec #LibreOffice

  • 1
  • 0
  • 0
  • 19h ago
Showing 1 to 10 of 42 CVEs