24h | 7d | 30d

Overview

  • NetScaler
  • ADC

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.53%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

Statistics

  • 21 Posts
  • 40 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CISA adds CVE-2026-88779 to the KEV Catalog. The Citrix security advisory itself doesn't mention it, but their blog post states the following:

Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

  • 1
  • 1
  • 0
  • 21h ago
Profile picture fallback

Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24 hours:

Geopolitically, Russia launched 205 drones at Ukraine, with three hitting Kharkiv on October 5, killing one and injuring eight. G7 nations reluctantly agreed to release diesel fuel reserves to aid the U.S. on October 4. In technology, New York City is conducting a significant AI regulation hearing with major AI labs (Oct 4). Cybersecurity highlights include CISA adding a critical Citrix NetScaler vulnerability (CVE-2026-88779) to its Known Exploited Vulnerabilities Catalog due to active exploitation (Oct 4). Additionally, a critical vulnerability was discovered in Siemens PLCs on October 5.

#AnonNews_irc #Cybersecurity #News

  • 1
  • 0
  • 0
  • 10h ago
Profile picture fallback

🚨 Citrix discloses high-severity NetScaler flaw tracked as CVE-2026-88779
⠀
CVE-2026-88779 is a memory overflow vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments. Successful exploitation can cause a denial-of-service condition. Citrix assigned it a CVSS v4.0 score of 8.7.
⠀
The vulnerability applies when the appliance is configured as either:
⠀
• A SAML Service Provider (SP)
• A SAML Identity Provider (IdP)
⠀
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with affected FIPS and NDcPP builds. Citrix is urging customers to install the updated releases as soon as possible.
⠀
CVE: CVE-2026-88779
Severity: High
CVSS v4.0: 8.7
Impact: Denial of Service
CWE: CWE-119

support.citrix.com/support-hom

  • 0
  • 3
  • 0
  • 22h ago
Profile picture fallback

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for CVE-2026-88779, a high-severity (CVSS 8.7) memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that has been exploited in targeted zero-day attacks. Successful exploitation can knock SAML-based deployments offline. Citrix urges administrators to apply the updates immediately. thehackernews.com/2026/10/new-

  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback

TheCyberMind.co™ Survival Series —Part 4

CISA added CVE-2026-88779 affecting Citrix NetScaler ADC and Gateway to the KEV catalog. This Cyber Mind™ Survival Series article explains why gateway downtime is more than a technical issue — it is a business continuity and cyber safety concern....

thecybermind.co/3is1

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway […]
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog - Security Affairs
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

📰 Citrix Patches Critical NetScaler Zero-Day Under Active Attack

Citrix patches critical zero-day (CVE-2026-88779) in NetScaler ADC & Gateway under active attack. The flaw can cause DoS & potential RCE. CISA added it to its KEV catalog, mandating federal agencies to patch by Oct 7. #NetScaler #ZeroDay #CVE

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-88779 – Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Immediate CISA KEV threat advisory for CVE-2026-88779 affecting Citrix NetScaler. Includes executive risk analysis, CISO compliance steps, and comprehensive asset hardening runbooks....

thecybermind.co/bl05

  • 0
  • 0
  • 1
  • 5h ago
Profile picture fallback

Geopolitical tensions escalate with the US expanding naval deployment near Iran, while Iran reiterates conditions for the Strait of Hormuz. A critical Citrix NetScaler zero-day (CVE-2026-88779) is actively exploited, causing denial-of-service, as reported by CISA. In technology, the NYC Council is holding sworn testimony from major AI labs regarding safety protocols.

#Cybersecurity #Geopolitics #AIGovernance

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

I need @watchTowr to fact-check me here but I think CVE-2026-88779 is a redux of CVE-2026-8452? At least based on this mitigation Citrix support are giving out, somebody posted it on their blog. deyda.net/index.php/de/2026/08

The 8452 patch locked SAML PrefixList to 512 byte or below string. But I think CVE-2026-88779 may be more than 15 items in PrefixList, space-separated, to trigger a vuln. Assuming Citrix support gave out the right mitigation.

  • 3
  • 17
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution.
  • 2
  • 5
  • 0
  • 23h ago
Profile picture fallback
~Cybergcca~ CVE-2026-88779 is actively exploited in Citrix NetScaler ADC and Gateway; patch immediately. - IOCs: CVE-2026-88779 - #CVE-2026-88779 #ThreatIntel
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
@sophossecurity.bsky.social Unpatched NetScaler appliances face active exploitation causing denial of service. - IOCs: CVE-2026-88779 - #CVE-2026-88779 #NetScaler #ThreatIntel
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
Citrix issued emergency fixes for CVE-2026-88779, a NetScaler SAML zero-day exploited in targeted attacks to cause denial of service. CISA added the flaw to its Known Exploited Vulnerabilities catalog. #Citrix #NetScaler #CISA
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
NetScaler SAML Authentication Issue: CVE-2026-88779 Exploited in the Wild(NetScalerのSAML認証にゼロデイ脆弱性、実際の攻撃で悪用) #SecurityOnline (Oct 4) securityonline.info/netscaler-sa...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
CVE-2026-88779 enables memory overflow in NetScaler SAML configurations, allowing targeted attacks that can cause denial of service and potentially remote code execution.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Citrix、攻撃で悪用されているNetScaler SAMLのゼロデイにパッチ:CVE-2026-88779 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47909/
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Citrix NetScaler appliances patched days earlier faced active exploitation of CVE-2026-88779, a high-severity memory overflow in ADC and Gateway SAML deployments. Attackers may have used related tooling for web shells and malware delivery. #Citrix
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Citrix released security updates for CVE-2026-88779, a high-severity memory overflow flaw in NetScaler ADC and Gateway exploited in targeted zero-day […]
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • rejetto
  • hfs

13 Jul 2026
Published
01 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.99%

KEV

Description

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

Statistics

  • 9 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical Rejetto HTTP File Server flaw (CVE-2026-61500, CVSS 9.3) is seeing active exploitation attempts, according to VulnCheck. The session-forgery bug stems from a weak pseudo-random number generator producing predictable keys, letting attackers gain unauthorized access and potentially achieve remote code execution. thehackernews.com/2026/10/atta

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

CVE-2026-61500 enables attackers to recover the session-cookie signing key, obtain administrative access and execute code remotely on Rejetto HFS.

Source: SecurityWeek
securityweek.com/exploitation-

#AI

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

📰 Attackers Actively Exploit Critical RCE Flaw in Rejetto HFS

Critical RCE flaw in Rejetto HFS (CVE-2026-61500, CVSS 9.3) is under active attack. A weak RNG allows attackers to forge admin cookies. A Chinese threat actor is targeting US servers. Patch to HFS version 3.2.1 now! #RCE #Vulnerability #CyberAttack

🔗 cyber.netsecops.io/articles/at

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]
Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It. - Security Affairs
  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE).
  • 1
  • 0
  • 0
  • Last hour
Profile picture fallback
CVE-2026-61500 enables session forgery in Rejetto HFS via predictable Math.random() output, allowing unauthorized admin access and remote code execution.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
CVE-2026-61500 in Rejetto HFS enables authentication bypass and remote code execution by leaking session-cookie signing material and allowing forged admin cookies.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Эксплуатация уязвимости Rejetto HFS, обнаруженной ИИ CVE-2026-61500 позволяет злоумышленникам восстановить ключ подписи сессионного cookie и получить административный доступ и удаленное выполнение кода. Telegram ИИ Дайджест #ai #news
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. Telegram AI Digest #ai #news
  • 0
  • 0
  • 0
  • Last hour

Overview

  • defunkt
  • gist

04 Oct 2026
Published
04 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.1)
EPSS
0.18%

KEV

Description

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

Statistics

  • 2 Posts
  • 54 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

WTF?

nvd.nist.gov/vuln/detail/cve-2

sev:CRIT 9.1 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.

  • 27
  • 27
  • 0
  • 8h ago
Profile picture fallback

CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Pending

16 Aug 2021
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
99.86%

Description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.

Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: thehackernews.com/2026/10/real

  • 0
  • 1
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Threat actors exploit patched Realtek Jungle SDK flaw CVE-2021-35394 to deploy Cling botnet malware using STUN-based command-and-control and multiple persistence methods.
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Threat actors are exploiting a critical Realtek SDK flaw (CVE-2021-35394) to deploy a new botnet malware called Cling. Cling repurposes […]
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • MikroTik
  • RouterOS

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.94%

KEV

Description

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

Statistics

  • 3 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated remote code execution vulnerability affecting MikroTik RouterOS web management.

Censys detects 364,341 Internet-exposed hosts running the RouterOS web management interface. Roughly 19,200 report RouterOS 7.x, and none currently report the patched 7.24 release or later.

The broader exposure count does not represent confirmed-vulnerable devices because the impact to RouterOS 6.x has not yet been established. No public exploitation has been reported.

Full Censys ARC advisory: censys.com/advisory/cve-2026-8

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-84411) MikroTik RouterOS Unauthenticated Root RCE via Web Management". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
🚨 RAPID RESPONSE: CVE-2026-84411 is a critical unauthenticated RCE affecting MikroTik RouterOS web management. Censys detects 364,341 exposed hosts. This is an exposure count, not confirmed vulnerable devices. No public exploitation reported. Censys ARC advisory: https://bit.ly/4rXOqaf
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Fortinet
  • FortiMail

01 Oct 2026
Published
05 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.20%

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Statistics

  • 3 Posts

Last activity: Last hour

Bluesky

Profile picture fallback
Fortinet「FortiMail」に重大な脆弱性CVE-2026-104286、サイバー攻撃で悪用-認証不要で任意ファイルを書き込み、CISA KEVに追加 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)(FortiMailの重大なゼロデイ脆弱性、実際の攻撃で悪用) #HelpNetSecurity (Oct 2) www.helpnetsecurity.com/2026/10/02/f...
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
📢 CVE-2026-104286 : Exploitation active d'une faille critique dans Fortinet FortiMail Rescana, publiée le 4 octobre 2026. L'article est une alerte d'exploitation active concernant CVE-2026-104286 (également référencée… 🟢 vérification factuelle haute #FortiMail #ExploitationActive #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Apple
  • iOS and iPadOS

28 Sep 2026
Published
01 Oct 2026
Updated

CVSS
Pending
EPSS
1.24%

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Meta caught someone burning a zero-day on Apple's graphics parser. Update your pocket glass so state surveillance has to spend another million dollars next week.
betanews.com/article/apple-pat

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Progress Software
  • @progress/sitefinity-nextjs-sdk

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

  • 1
  • 3
  • 0
  • 7h ago
Profile picture fallback

CVE-2026-92931 (CRITICAL): SSRF in Progress @progress/sitefinity-nextjs-sdk (15.1.8326 – 15.4.8637). Remote attackers may access internal resources. Monitor for patches & restrict egress where possible. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 7h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

02 Oct 2026
Published
03 Oct 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.50%

KEV

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 10 hours ago

Bluesky

Profile picture fallback
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) 📖 Read more: www.helpnetsecurity.com/2026/10/05/e... #cybersecurity #cybersecuritynews #MicrosoftExchange #securityupdate #vulnerability @microsoft.com
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback
Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940 https://gbhackers.com/microsoft-releases-emergency-exchange-server-update/
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
11.95%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Inyección de comandos no autenticados en servidores de correo con acceso a Internet: seguimiento de CVE-2026-73570. (Inglés)

Fuente: Microsoft Security (@msftsecurity)

microsoft.com/en-us/security/b

  • 0
  • 0
  • 1
  • 1h ago

Bluesky

Profile picture fallback
Zimbra CVE-2026-73570 Harvested the Signing Keys That Authenticate Every Session on the Platform – Forkast forkast.news/zimbra-cve-2...
  • 0
  • 0
  • 0
  • 12h ago
Showing 1 to 10 of 66 CVEs