Overview
Description
Statistics
- 10 Posts
- 95 Interactions
Fediverse
This is the patch that never ends
It goes on and on my friends
Some people
Started applying it
Not knowing what it was
And they will keep applying it
Forever just because
(CVE-2026-88779 advisory and patch included now)
https://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: https://doublepulsar.com/citrix-forgot-to-tell-you-cve-2025-6543-has-been-used-as-a-zero-day-since-may-2025-d76574e2dd2c
Citrix NetScaler CVE-2026-88779 is exploited in the wild against NetScaler SAML authentication setups. Upgrade to 14.1-73.41 now.
#Citrix #NetScaler #CVE202688779 #SAML #ActivelyExploited #DoS #Vulnerability
🚨 Citrix discloses high-severity NetScaler flaw tracked as CVE-2026-88779
⠀
CVE-2026-88779 is a memory overflow vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments. Successful exploitation can cause a denial-of-service condition. Citrix assigned it a CVSS v4.0 score of 8.7.
⠀
The vulnerability applies when the appliance is configured as either:
⠀
• A SAML Service Provider (SP)
• A SAML Identity Provider (IdP)
⠀
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, along with affected FIPS and NDcPP builds. Citrix is urging customers to install the updated releases as soon as possible.
⠀
CVE: CVE-2026-88779
Severity: High
CVSS v4.0: 8.7
Impact: Denial of Service
CWE: CWE-119
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
CVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway <14.1-73.41, <13.1-64.28, <13.1-37.282. Remote, unauthenticated attackers can disrupt availability. Patch required; no active exploits. https://radar.offseq.com/threat/cve-2026-88779-vulnerability-in-netscaler-adc-93f6c6cf8720e4e9 #OffSeq #NetScaler #Vulnerability #InfoSec
Einordnung: NetScaler-Zero-Day trifft Fernwartung
Citrix NetScaler: Zero-Day CVE-2026-88779 wird ausgenutzt. Wer SAML nutzt, sollte sofort auf 14.1-73.41 bzw. 13.1-64.28 patchen – auch die Fernwartung.
#OTSecurity #ICS #KRITIS #NIS2 #Cybersicherheit
https://ot-cyber.de/blog/einordnung-netscaler-zero-day-trifft-fernwartung.html
#Citrix die #Schwachstelle #CVE-2026-88779 im NetScaler ADC und NetScaler Gateway bestätigt. Führt zum Absturz, kann für Denial of Service-Angriffe missbraucht werden. Also patchen.
Bluesky
Overview
Description
Statistics
- 5 Posts
- 1 Interaction
Fediverse
2026-W40 — Weekly Threat Roundup
🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patch available yet, demanding immediate workarounds.
🏴☠️ Operation KillSwitch dismantled the KillSec ransomware gang, allegedly run by a 16-year-old, seizing 110TB of stolen victim data.
🇨🇳 China-linked Warlock…
https://threatnoir.com/weekly/2026-w40
#infosec #cybersecurity #threatintel
🤖 AI generated summary
Another week; another Fortinet vulnerability.
Fortinet disclosed CVE-2026-104286 on Oct. 1 and confirmed active exploitation. Path-traversal lets unauthenticated attackers write arbitrary files, which can lead to command execution. Until fixes arrive, disable IBE or restrict the management interface to trusted networks. Preserve evidence and review Fortinet’s IoCs; mitigation does not erase a compromise.
Geopolitical tensions are escalating with intensified fighting in Yemen, as Iran reiterates that there is "no military solution" to the ongoing conflict. In technology, OpenAI has halted the release of its GPT-6.1 Astra model citing safety concerns, highlighting the growing scrutiny of advanced AI. On the cybersecurity front, a suspected ShinyHunters hacker has been detained in Jordan, assisting the FBI. Urgent action is also advised for an exploited critical FortiMail zero-day vulnerability (CVE-2026-104286).
Bluesky
Overview
- GitLab
- GitLab AI Gateway
Description
Statistics
- 3 Posts
- 5 Interactions
Fediverse
POV: you shipped an AI gateway
the prompt template: "hi {{name}}"
a logged in user with a crafted flow config: "what if i was a shell"
gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19.3.1, 19.4.0. fixed in 19.2.4, 19.3.2, 19.4.1. gitlab.com and dedicated already patched
Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION - Security Affairs
⚠️ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab disclosed CVE-2026-90970, a critical RCE in AI Gateway that lets authenticated users with Duo Agent Platform access break out of prompt sandbox and run arbitrary commands. Self-hosted deployments are vulnerable; cloud instances are already patched. This is the second critical GitLab vuln in…
🤖 AI generated summary
Overview
Description
Statistics
- 3 Posts
- 4 Interactions
Fediverse
I didn’t realize the EU CERT was so witty!
https://cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
(analysis of the NetScaler thing from last week.)
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
Zammad security alert: session hijacking and remote code execution
CVE-2026-102489 concerns session hijacking that can lead to code execution as the Zammad service account on affected older installations. DIVD reports exploitation in a real incident.
Zammad states that version 7.0 and later are not exploitable through this issue and recommends upgrading to 7.2.0.
#Zammad #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator
Overview
Description
Statistics
- 1 Post
- 56 Interactions
Fediverse
The new Citrix Netscaler vuln from Friday is CVE-2026-88779, patch is out now and they recommend patching as soon as possible: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
Although the vuln is labeled “Memory overflow vulnerability leading to Denial of Service”, that’s the same as CVE-2025–6543. You may remember that lead to RCE in the wild. Prior blog on that: https://doublepulsar.com/citrix-forgot-to-tell-you-cve-2025-6543-has-been-used-as-a-zero-day-since-may-2025-d76574e2dd2c
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Discover how a single encoded character exploited a critical Cisco zero-day vulnerability in the Catalyst SD-WAN Manager, granting attackers admin access.
Overview
- Legion of the Bouncy Castle Inc.
- BC-JAVA
- bcmls
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CVE-2026-71885 (CRITICAL): Bouncy Castle for Java <1.86 suffers from X.509 credential binding flaw in MLS. Attackers can impersonate users & decrypt group messages. Upgrade to v1.86+ now. https://radar.offseq.com/threat/in-bouncy-castle-for-java-before-186-the-messaging-layer-security-mls-rfc-9420-implementation-did-not-53cae24ecd925b00 #OffSeq #BouncyCastle #Java #Infosec
Overview
- vincent-peugnet
- wcms
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
vincent-peugnet wcms ≤3.18.0 is vulnerable (CVE-2026-105123, HIGH, CVSS 8.7): Authenticated editors can upload malicious files via /api/v0/media/upload/ and delete arbitrary files. Restrict privileges, monitor uploads. https://radar.offseq.com/threat/cve-2026-105123-unrestricted-upload-of-file-with-dangerous-type-in-vincent-peugnet-wcms-9cc4f5671e51d0dd #OffSeq #RCE #WebSecurity #Vuln
Overview
- The Document Foundation
- LibreOffice
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-63272 LibreOffice heap buffer overflow when importing WMF graphics in documents. CVSS 5.3. No patch yet. Avoid untrusted files and update as soon as a fix ships. https://www.valtersit.com/cve/CVE-2026-63272/ #CVE #infosec #LibreOffice