Overview
- NetScaler
- ADC
Description
Statistics
- 17 Posts
- 65 Interactions
Fediverse
There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406
Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.
I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:
CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
https://support.citrix.com/external/article/CTX697191
https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability
#Murmeltier-Tag Kritische #Schwachstelle CVE-2026-107406 (CVSS 9.4) in #Citrix NetScaler ADC / Citrix NetScaler Gateway (8.10.2026) wenn diese Appliances als SAML-SP oder SAML-IdP konfiguriert sind. Also patchen.
And here we go again... https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_107406 It would seem that the "timely reaction" to last weekend's vuln resulted in an incomplete fix. #citrix #netscaler #srsly #ythough
Citrix has urged customers to update NetScaler ADC and Gateway for CVE-2026-107406, a serious flaw that could allow remote code execution or service disruption.
For versions 14.1-73.37–14.1-73.41 and 13.1-64.23–13.1-64.28, exposure applies when configured as a SAML IdP; older supported releases may also be affected when configured as a SAML SP or IdP.
For the standard 14.1 and 13.1 branches, fixed releases are 14.1-73.46+ and 1…
https://en.hacks.gr/i-citrix-zita-enimerosi-gia-to-netscaler-meta-apo-sovaro-provlima-asfaleias/
Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments
Citrix patches CVE-2026-107406, a critical NetScaler memory overflow flaw rated CVSS 9.5 that can enable remote code execution or denial of servicehttps://thecybersecguru.com/exploits/citrix-netscaler-cve-2026-107406-rce/
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability - Security Affairs
Citrix has released fixes for CVE-2026-107406, a memory overflow flaw in NetScaler ADC and NetScaler Gateway.
Under specific configurations, it could allow remote code execution or denial of service.
The issue requires NetScaler to be configured as a SAML identity provider or service provider; affected releases vary by role and product branch.
It is rated 9.5/10.
There is no evidence the flaw has been exploited in real-world…
CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212
Bluesky
Overview
- Telegram
- Telegram Desktop
Description
Statistics
- 5 Posts
- 5 Interactions
Fediverse
A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.
#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC
Telegram Desktop’s CVE-2026-107181 affects versions before 7.2.9.
A specially crafted link opened outside Telegram could allow local-file theft; account takeover was possible if no local lock code was enabled.
Links opened inside Telegram were not affected.
The demonstrated attack used Windows and was not shown on macOS or Linux.
It also depended on specific group auto-download and invitation settings.
Te…
Por cierto, si usan Telegram con regularidad en su versión desktop y estás por debajo de la versión v7.2.9 deberían actualizar inmediatamente, hay una vulnerabilidad enorme en las versiones anteriores a esta versión
https://www.cve.org/CVERecord?id=CVE-2026-107181
#telegram
🚨 PoC released for Telegram Desktop account takeover vulnerability; CVE-2026-107181
https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
A vulnerability in Telegram Desktop allows attackers to steal local files, including session keys, by tricking users into opening a specially crafted tg:// link.
Stolen session data could allow attackers to hijack Telegram accounts without knowing the victim's password.
CVSS: 8.1 (High, v3.1) / 8.6 (High, v4.0)
Affected: Telegram Desktop before 7.2.9
Fixed: Version 7.2.9
The published PoC demonstrates how a malicious link can trigger file exfiltration through Telegram's IPC handler.
Overview
Description
Statistics
- 6 Posts
- 8 Interactions
Fediverse
SonicWall’s latest critical flaw indicates a security pattern, not another one-off bug
SonicWall has disclosed yet another critical flaw in a core product, CVE-2026-102255, rated a maximum 10.0, which CSO Online argues points to a deeper security pattern rather than an isolated bug. The repeated critical issues raise questions about the vendor’s secure development practices. https://www.csoonline.com/article/4232246/sonicwalls-latest-critical-flaw-indicates-a-security-pattern-not-another-one-off-bug.html
Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.
Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/
Bluesky
Overview
- Atlassian
- Bamboo Data Center
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
Threat actors began exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products, just hours after technical details went public, Security Affairs reports. The rapid weaponization leaves administrators a razor-thin patching window. https://securityaffairs.com/200591/security/atlassian-vulnerability-comes-under-attack-hours-after-details-go-public.html
Overview
- Ahsay
- AhsayCBS
Description
Statistics
- 4 Posts
Fediverse
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are exploiting critical AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers, Huntress reports. Administrators are urged to update to version 10.3.4 and restrict access to exposed servers. https://www.huntress.com/blog/ahsaycbs-flaws-exploit
Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Unknown attackers are exploiting two AhsayCBS backup-software flaws: CVE-2026-105133 (CVSS v4 5.5) and CVE-2026-105134 (9.3).
Used together, they can bypass authentication and allow commands on affected systems.
Huntress says attempts began on Oct.
7; by Oct.
8, five organizations were estimated to be affected.
After gaining access, attackers installed XMRig for cryptocurrency mining, disguised as “edge.exe.” Patch in…
https://en.hacks.gr/agnostoi-parakamptoyn-ti-syndesi-sto-ahsaycbs-kai-exoryssoyn-kryptonomismata/
Overview
- Microsoft
- Microsoft Dataverse
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! https://radar.offseq.com/threat/cve-2026-88131-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-dataverse-eba5097c3e4671bb #OffSeq #CVE202688131 #Microsoft #RCE #Infosec
CVE-2026-88131 - Critical RCE in Microsoft Dataverse via insecure deserialization. CVSS 9.8. Unpatched vulnerability. Mitigate immediately. #CVE #Microsoft #infosec
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-96207 (10.0 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-94510 (9.9 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77900 (9.8 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-88131 (9.8 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69435 (9.6 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83943 (8.7 high)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83947 (7.7 high)
Overview
- Meta
- react-server-dom-turbopack
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-23870 is a denial-of-service flaw in React Server Components.
A crafted remote POST request can trigger excessive processing and freeze vulnerable Next.js servers.
Affected versions include React 19.0.0–19.0.5, 19.1.0–19.1.6 and 19.2.0–19.2.5, including some Next.js deployments using Server Actions.
Possible effects include slow pages, timed-out requests and HTTP 503 errors.
Fixed React releases are 19.0.6, 19.1.…
React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request
A high-severity denial-of-service flaw, CVE-2026-23870, in React Server Components lets a remote attacker freeze vulnerable Next.js servers with a single specially crafted POST request, CyberSecurity News reports. The finding underscores the exposure hiding in widely used web frameworks. https://cybersecuritynews.com/react-server-components-dos-vulnerability/
Overview
- Ahsay
- AhsayCBS
Description
Statistics
- 3 Posts
Fediverse
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are exploiting critical AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers, Huntress reports. Administrators are urged to update to version 10.3.4 and restrict access to exposed servers. https://www.huntress.com/blog/ahsaycbs-flaws-exploit
Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Unknown attackers are exploiting two AhsayCBS backup-software flaws: CVE-2026-105133 (CVSS v4 5.5) and CVE-2026-105134 (9.3).
Used together, they can bypass authentication and allow commands on affected systems.
Huntress says attempts began on Oct.
7; by Oct.
8, five organizations were estimated to be affected.
After gaining access, attackers installed XMRig for cryptocurrency mining, disguised as “edge.exe.” Patch in…
https://en.hacks.gr/agnostoi-parakamptoyn-ti-syndesi-sto-ahsaycbs-kai-exoryssoyn-kryptonomismata/
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at https://x41-dsec.de/lab/research/2026/10/07/badhost/
Overview
- Microsoft
- Microsoft Partner Center
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. https://radar.offseq.com/threat/cve-2026-96207-cwe-295-improper-certificate-validation-in-microsoft-microsoft-partner-center-0f13dc5f1a15e1f3 #OffSeq #Microsoft #CVE202696207 #Infosec
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-96207 (10.0 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-94510 (9.9 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-77900 (9.8 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-88131 (9.8 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69435 (9.6 critical)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83943 (8.7 high)
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-83947 (7.7 high)