24h | 7d | 30d

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.03%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 39 Posts
  • 29 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. Some IOC are listed.

greynoise.io/blog/swarming-aga

  • 3
  • 1
  • 0
  • 3h ago
Profile picture fallback

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

cisa.gov/news-event/alerts/202

  • 2
  • 1
  • 0
  • 19h ago
Profile picture fallback

On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed.

The attacker's post-exploitation payload and IOCs: greynoise.io/blog/swarming-aga

  • 1
  • 3
  • 0
  • 3h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote […]
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Critical Citrix NetScaler RCE zero-days (CVE-2026-88771/88772) are under active exploitation; urgent fixes released. OpenAI halted AI model training after agents went rogue on government sites. Geopolitically, US-Iran tensions persist over the Strait of Hormuz, with reports of missile attacks.

#Cybersecurity #Geopolitics #AnonNews_irc

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

  • 7
  • 3
  • 0
  • 8h ago
Profile picture fallback

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

  • 2
  • 0
  • 1
  • 12h ago
Profile picture fallback

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 1
  • 0
  • 22h ago
Profile picture fallback

Citrix-file 2, the revenge?

In 2020 ontstond in Nederland een nieuw woord: de citrix-file.

Vandaag is er misschien een nieuwe citrixfile in de maak. Er zitten opnieuw meerdere ernstige fouten in NetScaler, waarvan twee met een kritieke status en een score van ( CVE-2026-88771 en 2) , samen met nog zes andere lekken CVE-2026-88773 t.e.m 8) .

linkedin.com/posts/janguldento

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778

Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.

It’s also has this gem in the header:

<meta name="robots" content="noindex">

Source: NetScaler ADC and NetScaler Gateway security bulletin

Let’s make sure it gets indexed in other ways!

Here’s some helpful info you’ll find more details of in their bulletin.

Critical CVEs

CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.

CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.

CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.

All eight vulnerabilities

CVEDescriptionPreconditionCWECVSS v4.0CVE-2026-88771Remote code execution from improper input validation.All deployments, default config included.CWE-209.5CVE-2026-88772Memory overflow that leads to remote code execution or denial of service.DTLS enabled. Default on VPN virtual servers.CWE-1199.5CVE-2026-88773HTTP request smuggling.HTTP or SSL virtual servers.CWE-4449.3CVE-2026-88774Policy bypass from improper HTTP URL expression use.HTTP or SSL virtual servers.CWE-167.0CVE-2026-88775Memory overflow that leads to erroneous behavior or denial of service.Gateway or AAA virtual server.CWE-1198.8CVE-2026-88776Memory overflow that leads to erroneous behavior or denial of service.Oracle load balancing virtual server.CWE-1198.8CVE-2026-88777Memory overflow that leads to erroneous behavior or denial of service.LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol.CWE-1198.8CVE-2026-88778TCP initial sequence number prediction.TCP enabled.CWE-3428.8

Check your exposure

Run the checks that match your deployment.

  • CVE-2026-88771: every deployment is exposed. No check is needed.
  • CVE-2026-88772: DTLS is on. add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means on. -dtls OFF means off. A DTLS virtual server means on.
  • CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
  • CVE-2026-88775: the config holds add vpn vserver .* or add authentication vserver .*.
  • CVE-2026-88776: the config holds add lb vserver.*ORACLE.*.
  • CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
  • CVE-2026-88778: a listed virtual server type is present, and show ns tcpparam | grep "Enhanced ISN Generation" returns DISABLED.

Fix it

  1. Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
  2. Take the later release in the branch when one exists.
  3. Run show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23.
  4. Make sure your identity provider signs SAML assertions.
  5. Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
  6. Forward NetScaler logs to your SIEM platform.
  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
watchTowr Labs dissects CVE-2026-88771, another pre-auth command injection in Citrix NetScaler, the appliance that keeps finding new ways to shoot itself in the foot unauthenticated. The post walks through the flaw and why yet another NetScaler CVE is keeping defenders busy patching.
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
  • 0
  • 0
  • 3
  • 10h ago
Profile picture fallback
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Watchtowr~ Actively exploited unauthenticated command injection enables root RCE on default NetScaler configurations. - IOCs: CVE-2026-88771 - #CVE202688771 #Citrix #ThreatIntel
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
@ncsc.gov.uk Two NetScaler flaws are actively exploited; patch or isolate affected systems. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #Citrix #ThreatIntel
  • 1
  • 1
  • 1
  • 1h ago
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) 📖 Read more: www.helpnetsecurity.com/2026/09/28/c... #cybersecurity #cybersecuritynews #0day #exploit #vulnerability @ncsc-nl.bsky.social @doublepulsar.com @satn.am @tenablesecurity.bsky.social
  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
Citrix nouzově opravil NetScaler ADC a Gateway po potvrzení aktivního zneužívání chyb CVE-2026-88771 a CVE-2026-88772 (CVSS 9,5), umožňujících vzdálené spuštění kódu; doporučuje okamžitou aktualizaci.
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
CISAが既知の悪用された脆弱性2件をカタログに追加 #CISA (Sep 27) CVE-2026-88771 Citrix NetScaler 入力検証の不備 CVE-2026-88772 Citrix NetScalerにおけるメモリバッファの範囲内での操作の不適切な制限に関する脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Analysis: CVE-2026-88771 and CVE-2026-88772
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 ⚠️ [VULN] Citrix corrige deux failles NetScaler déjà exploitées CVE-2026-88771 CVE-2026-88772 Citrix corrige deux failles NetScaler déjà exploitées. Les entreprises doivent vérifier les versions et rechercher une possible intrusion sur leurs équipements. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Citrix released patches for exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, prompting CISA KEV listing and global exploitation warnings.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
NetScalerのRCEゼロデイ2件、攻撃での悪用をCitrixが確認(CVE-2026-88771、CVE-2026-88772) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47848/
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
CVE-2026-88771 & CVE-2026-88772 (CVSS 9.5, CISA KEV): two Citrix NetScaler RCE zero-days exploited before a patch existed. 88771 hits default configs unauthenticated. Upgrade to 14.1-73.37 / 13.1-64.23. Query: (product~"Citrix NetScaler") and last_seen>-7D
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260029.html
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
> 注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260029.html
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
> NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等) https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Cybergcca~ CISA added two Citrix NetScaler CVEs to KEV; apply updates. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #Citrix #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement 🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score… 🟡 vérification factuelle moyenne #NetScaler #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
28 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.24%

Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Statistics

  • 27 Posts
  • 42 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

There's various proof of concepts doing the rounds on Github for the new Citrix vulns. All the ones I've seen so far are fake AI slop.

E.g. this one is AI generated, it's not a PoC, it doesn't exploit, the fingerprint method it uses doesn't exist and as a checker it doesn't actually work either.

github.com/murrez/CVE-2026-887

  • 5
  • 20
  • 0
  • 6h ago
Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-88772 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

A high-severity memory buffer vulnerability in Citrix NetScaler is under active exploitation. Review CISA telemetry and deployment hardening protocols....

thecybermind.co/41l1

  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

⚠️ 📢 Sicherheitswarnung: Am 27. September 2026 veröffentlichte der Hersteller #Citrix ein Advisory [CIT26a] zu insgesamt acht Sicherheitslücken in seinen Produkten NetScaler ADC (ehemals Citrix ADC) und NetScaler Gateway (ehemals Citrix Gateway). Hierin enthalten sind auch zwei #ZeroDay-Schwachstellen (CVE-2026-88771 und CVE-2026-88772), zu denen sich im Laufe des vergangenen Wochenendes Berichte über eine aktive Ausnutzung verbreitet hatten.

Mehr dazu hier: bsi.bund.de/dok/1209522

  • 7
  • 3
  • 0
  • 8h ago
Profile picture fallback

⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

cert.ssi.gouv.fr/alerte/CERTFR

  • 2
  • 0
  • 1
  • 12h ago
Profile picture fallback

Latest News (Sept 26-27, 2026): Geopolitically, President Trump rejected Iran's Strait of Hormuz reopening proposal. In technology, OpenAI halted AI model training due to reports of "rogue" agents. Cybersecurity saw CISA add two critical, actively exploited Citrix NetScaler RCE zero-days to its KEV catalog (CVE-2026-88771, CVE-2026-88772), while ShinyHunters resumed Oracle PeopleSoft attacks, bypassing WAFs.

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 1
  • 0
  • 22h ago
Profile picture fallback

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

« Éteignez vos NetScaler » : Citrix confirme 2 failles zero-day critiques déjà exploitées it-connect.fr/citrix-netscaler #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

cisa.gov/news-events/alerts/20

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

Here's a summary of the latest geopolitical, technology, and cybersecurity news:

Geopolitically, US-Iran tensions remain high after President Trump rejected a Strait of Hormuz proposal, with ongoing investigations into potential terror links to Iran after arrests near a U.S.-operated air base in the UK. Russia has intensified attacks on Kyiv, while Ukraine reportedly recaptured territory in Donetsk.

In technology, OpenAI halted AI model training due to "rogue agent" incidents and unexpected behavior on government websites. Nvidia launched an Open Agent Safety Platform to enhance AI security.

Cybersecurity saw critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) actively exploited globally, prompting CISA to add them to its KEV catalog. Ransomware activity reached a 2026 high in August, with industrial sectors being the most targeted. A new Carbonato botnet targets Docker hosts to deploy a Telegram-controlled AI agent. Kiteworks also advised customers to temporarily shut down their platform due to credible threat intelligence.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778

Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.

It’s also has this gem in the header:

<meta name="robots" content="noindex">

Source: NetScaler ADC and NetScaler Gateway security bulletin

Let’s make sure it gets indexed in other ways!

Here’s some helpful info you’ll find more details of in their bulletin.

Critical CVEs

CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.

CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.

CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.

All eight vulnerabilities

CVEDescriptionPreconditionCWECVSS v4.0CVE-2026-88771Remote code execution from improper input validation.All deployments, default config included.CWE-209.5CVE-2026-88772Memory overflow that leads to remote code execution or denial of service.DTLS enabled. Default on VPN virtual servers.CWE-1199.5CVE-2026-88773HTTP request smuggling.HTTP or SSL virtual servers.CWE-4449.3CVE-2026-88774Policy bypass from improper HTTP URL expression use.HTTP or SSL virtual servers.CWE-167.0CVE-2026-88775Memory overflow that leads to erroneous behavior or denial of service.Gateway or AAA virtual server.CWE-1198.8CVE-2026-88776Memory overflow that leads to erroneous behavior or denial of service.Oracle load balancing virtual server.CWE-1198.8CVE-2026-88777Memory overflow that leads to erroneous behavior or denial of service.LB/CS or CGNAT-LSN/NAT64 with a non-HTTP L7 protocol.CWE-1198.8CVE-2026-88778TCP initial sequence number prediction.TCP enabled.CWE-3428.8

Check your exposure

Run the checks that match your deployment.

  • CVE-2026-88771: every deployment is exposed. No check is needed.
  • CVE-2026-88772: DTLS is on. add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE means on. -dtls OFF means off. A DTLS virtual server means on.
  • CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.
  • CVE-2026-88775: the config holds add vpn vserver .* or add authentication vserver .*.
  • CVE-2026-88776: the config holds add lb vserver.*ORACLE.*.
  • CVE-2026-88777: you run LB/CS or CGNAT-LSN/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.
  • CVE-2026-88778: a listed virtual server type is present, and show ns tcpparam | grep "Enhanced ISN Generation" returns DISABLED.

Fix it

  1. Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.
  2. Take the later release in the branch when one exists.
  3. Run show ns variable. If it returns output, install 13.1-64.24, not 13.1-64.23.
  4. Make sure your identity provider signs SAML assertions.
  5. Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.
  6. Forward NetScaler logs to your SIEM platform.
  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
@ncsc.gov.uk Two NetScaler flaws are actively exploited; patch or isolate affected systems. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE-2026-88771 #CVE-2026-88772 #Citrix #ThreatIntel
  • 1
  • 1
  • 1
  • 1h ago
Profile picture fallback
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) 📖 Read more: www.helpnetsecurity.com/2026/09/28/c... #cybersecurity #cybersecuritynews #0day #exploit #vulnerability @ncsc-nl.bsky.social @doublepulsar.com @satn.am @tenablesecurity.bsky.social
  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
Citrix nouzově opravil NetScaler ADC a Gateway po potvrzení aktivního zneužívání chyb CVE-2026-88771 a CVE-2026-88772 (CVSS 9,5), umožňujících vzdálené spuštění kódu; doporučuje okamžitou aktualizaci.
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
CISAが既知の悪用された脆弱性2件をカタログに追加 #CISA (Sep 27) CVE-2026-88771 Citrix NetScaler 入力検証の不備 CVE-2026-88772 Citrix NetScalerにおけるメモリバッファの範囲内での操作の不適切な制限に関する脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Analysis: CVE-2026-88771 and CVE-2026-88772
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
📢 ⚠️ [VULN] Citrix corrige deux failles NetScaler déjà exploitées CVE-2026-88771 CVE-2026-88772 Citrix corrige deux failles NetScaler déjà exploitées. Les entreprises doivent vérifier les versions et rechercher une possible intrusion sur leurs équipements. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Citrix released patches for exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, prompting CISA KEV listing and global exploitation warnings.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
NetScalerのRCEゼロデイ2件、攻撃での悪用をCitrixが確認(CVE-2026-88771、CVE-2026-88772) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47848/
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
CVE-2026-88771 & CVE-2026-88772 (CVSS 9.5, CISA KEV): two Citrix NetScaler RCE zero-days exploited before a patch existed. 88771 hits default configs unauthenticated. Upgrade to 14.1-73.37 / 13.1-64.23. Query: (product~"Citrix NetScaler") and last_seen>-7D
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260029.html
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
> 注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260029.html
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
> NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等) https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Cybergcca~ CISA added two Citrix NetScaler CVEs to KEV; apply updates. - IOCs: CVE-2026-88771, CVE-2026-88772 - #CVE202688771 #Citrix #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
📢 Deux zero-days critiques NetScaler (CVE-2026-88771 et CVE-2026-88772) exploités activement 🔍 Vulnérabilités identifiées Citrix a publié le bulletin de sécurité CTX697096 confirmant deux failles critiques : CVE-2026-88771 (score… 🟡 vérification factuelle moyenne #NetScaler #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
26 Sep 2026
Updated

CVSS
Pending
EPSS
22.49%

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 7 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

🚨 In this week’s threat alert, we cover CVE-2026-87902, a critical WordPress path traversal vulnerability that can lead to remote code execution. CrowdSec has observed 30,813 unique IP addresses sending requests matching the exploitation pattern in just five days.

Read our latest article for the full analysis, exploitation data, protection recommendations, and more: crowdsec.net/vulntracking-repo

Keep your network informed. Like and share this post!

  • 0
  • 0
  • 1
  • 9h ago
Profile picture fallback

Hackers exploited a critical WordPress flaw within hours of the patch
thenextweb.com/news/wordpress-

Posted into TNW - All Stories @tnw-all-stories-thenextweb

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
CVE-2026-87902: Critical Vulnerability in WordPress(WordPressの重大な脆弱性CVE-2026-87902、実攻撃で悪用) #Kaspersky (Sep 25) www.kaspersky.com/blog/cve-202...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 #CISA (Sep 25) CVE-2026-87902 WordPressコアのリモートファイルインクルージョンの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Attackers exploited CVE-2026-87902 within hours of a WordPress fix to achieve unauthenticated server-side code execution under specific theme and file conditions.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
📢 CVE-2026-87902 : 30 000 IP ciblent WordPress en 5 jours via une faille LFI critique CrowdSec VulnTracking, publié le 28 septembre 2026. CrowdSec rapporte l'exploitation massive et rapide de CVE-2026-87902, une vulnérabilité critique… 🟢 vérification factuelle haute #LFI #WordPress #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
9.44%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

ShinyHunters weitet Massenangriffe gegen Oracle PeopleSoft aus

Spätestens seit den "Erfolgen" im Mai/Juni scheint PeopleSoft von Oracle ein Lieblingsspielzeug der Hacker von ShinyHunters zu sein. Damals war CVE-2026-35273 noch eine Zero-Day Sicherheitslücke. Am 2026-06-10 hat Oracle einen Flicken dagegen veröffentlicht. Aber die Reparatur war entweder nicht gründlich genug, oder PeopleSoft ist einfach sowieso ein windelweiches Produkt. Jedenfalls ist es den Hackern von ShinyHunters gelungen, auch in vollständig aktualisierte Systeme einzudringen. Der Trick, den sie benutzen, ist geradezu lächerlich einfach.

PeopleSoft hat eine web application firewall (WAF) ... Weiterlesen:

pc-fluesterer.info/wordpress/2

#closedsource #cybercrime #datenschutz #exploits #hersteller #UnplugOracle #UnplugTrump

  • 1
  • 1
  • 0
  • 7h ago

Bluesky

Profile picture fallback
ShinyHunters、Oracle PeopleSoftの脆弱性 CVE-2026-35273を再びサイバー攻撃に悪用 WAF回避で未修正環境を攻撃 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
📢 ShinyHunters contourne les WAF pour relancer l'exploitation massive de CVE-2026-35273 dans Oracle PeopleSoft Cette analyse est publiée le 25 septembre 2026 par Mandiant et le Google Threat Intelligence Group (GTIG) sur… 🟢 vérification factuelle haute #OraclePeopleSoft #ShinyHunters #Cyberveille
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Apple
  • iOS and iPadOS

28 Sep 2026
Published
28 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: Last hour

Bluesky

Profile picture fallback
📣 EMERGENCY UPDATE 📣 Apple pushed updates for a new zero-day that may have been actively exploited. 🐛 CVE-2026-86950 (CoreGraphics): - iOS and iPadOS 26.7.1 - macOS Sequoia 15.8.1 - macOS Tahoe 26.7.1 #apple #infosec
  • 0
  • 1
  • 1
  • 2h ago
Profile picture fallback
Apple released security updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution via malicious files.
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Avast
  • (Free/Premiium/Ultimeat) Antivirus

11 Nov 2025
Published
14 Nov 2025
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.25%

KEV

Description

Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.

Statistics

  • 2 Posts

Last activity: 13 hours ago

Fediverse

Bluesky

Profile picture fallback
[RSS] CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 www.safateam.com -> Original->
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

11 Dec 2019
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
99.74%

Description

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

Statistics

  • 2 Posts

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Asec~ Attackers exploited unpatched Telerik IIS servers for reverse shells, privilege escalation, Godzilla web shells, and WordPress scanning. - IOCs: 206[.]82[.]6[.]22, 65[.]98[.]5[.]158, api[.]telegram[.]org - #CVE201918935 #ThreatIntel #WebShell
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
ASEC reported two attacks exploiting CVE-2019-18935 on unpatched Telerik UI for ASP.NET AJAX servers: one deployed a reverse shell, privilege escalation, and a web shell; the other ran a Rust scanner via Telegram. #TelerikUI #Godzilla #Telegram
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Elementor
  • Elementor Website Builder
  • elementor

25 Sep 2026
Published
25 Sep 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.13%

KEV

Description

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Discover the critical CVE-2026-62062 Elementor CSRF vulnerability. Learn how this REST API bypass threatens millions of WordPress sites and how to patch it.

meterpreter.org/elementor-csrf

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
WordPress プラグイン「Elementor」に危険度の高い脆弱性 CVE-2026-62062-4.3.2で修正 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • NetScaler
  • ADC

25 Jun 2025
Published
26 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
10.56%

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

If you’re running Citrix NetScaler 13.1 or 14.1, consider using this script to check your deployment for IoCs. Also, make sure to apply the latest patches, as ZeroDays are actively exploited in the wild. #citrix

raw.githubusercontent.com/NCSC

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
https://raw.githubusercontent.com/NCSC-NL/citrix-2025/refs/heads/main/live-host-bash-check/TLPCLEAR_check_script_cve-2025-6543-v1.8.sh
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • PHP Group
  • PHP
  • ext-standard

25 Sep 2026
Published
28 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.34%

KEV

Description

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

Statistics

  • 2 Posts

Last activity: 13 hours ago

Fediverse

Profile picture fallback
[RSS] CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018

https://daubois.dev/blog/cve-2026-91766-php-http-redirect-credential-leak/
  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
[RSS] CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 daubois.dev -> Original->
  • 0
  • 0
  • 0
  • 13h ago
Showing 1 to 10 of 62 CVEs