
Citrix Fixes Two Exploited Zero-Days in NetScaler
Citrix published fixes for CVE-2026-88771 and CVE-2026-88772, critical remote execution vulnerabilities in NetScaler ADC and Gateway that were exploited pre-patch.
Security & Risk
143 analyses

Citrix published fixes for CVE-2026-88771 and CVE-2026-88772, critical remote execution vulnerabilities in NetScaler ADC and Gateway that were exploited pre-patch.

September 25 update expands Hugging Face case: OpenAI engaged SEC.gov and Census.gov, while Australia learned 54 days later of access to Medicare portal's non-public files.

CVE-2026-65660, rated 6.5 by Microsoft in August, is actively exploited remote code execution. CISA has given federal agencies until September 28 to patch it.

The U.S. agency included critical vulnerabilities in WSO2 API gateways and Adobe Commerce that allow account takeovers based on evidence of active exploitation.

Americana Astrana Health reported a material cyber incident to the SEC: criminals spoofed the company’s number and posed as employees to gain system access.

NCC Group report reveals 1,073 ransomware victims in August, a 12% increase over July and the highest count of the year. The industrial sector accounted for 31% of cases, with Qilin and The Gentlemen leading.

An unprotected config key allowed any local process on a Mac to redirect audio to Meta's agent, inheriting access to Mail, Files, and Messages.

CVE-2026-94127 allows remote code execution without authentication. U.S. federal agencies have until September 25 to patch.

The group claims control of Clop's Tor site and threatens to reveal companies that paid ransoms during attacks on Oracle E-Business Suite. Clop responded but did not confirm the extent.

On September 20, Qilin named the Turkish conglomerate and the largest Swiss mobility club with 1.6 million members. Neither organization has commented.

Google revealed that Gemini accessed systems of three real companies in May during a security assessment, after a bug exposed the agent to the public Internet. Meta, Anthropic, and OpenAI reported similar incidents with the same evaluator.

API authentication bypass in Identity Services Engine allows root access without credentials. Cisco offers no workaround, and CISA included the flaw in KEV with a deadline of September 19.