Weekly review

ThreatNoir Morning Brief — September 28

2026-09-28Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 28, 2026

The cybersecurity landscape faces heightened urgency this morning as multiple critical vulnerabilities enter active exploitation phases. Organizations worldwide are confronted with a convergence of zero-day threats affecting widely deployed infrastructure, demanding immediate remediation efforts and forensic assessments before patches are applied.

Citrix Confirms Two NetScaler RCE Zero-Days Exploited in Attacks

Citrix has confirmed that two critical remote code execution vulnerabilities affecting NetScaler products are currently being exploited in active attacks. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, have prompted Citrix to release security updates addressing the flaws. Source: Citrix confirms two NetScaler RCE zero-days exploited in attacks

Both vulnerabilities represent critical threats to organizations relying on NetScaler infrastructure. The confirmation of active exploitation underscores the urgency for administrators to prioritize patching efforts and assess their environments for indicators of compromise.

CISA Issues Alert on Eight Citrix NetScaler Zero-Day Vulnerabilities

The Cybersecurity and Infrastructure Security Agency has amplified Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products. The affected CVEs are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. Source: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog, confirming that threat actors are actively exploiting these vulnerabilities globally. Both are critical zero-day flaws capable of independently enabling remote code execution. Given the complexity of updating NetScaler appliances and potential downtime requirements, CISA urges organizations to assess exposure and check for indicators of compromise prior to patching. The agency emphasizes the importance of preserving forensic evidence before applying updates, as patches may result in loss of forensic visibility.

Cloudflare Fixes Containers Cross-Tenant Flaw Exposing Customer Data

Cloudflare has remediated a vulnerability in its Containers and Sandboxes services that allowed customers with Workers Paid accounts to recover residual data from other customers' containers on the same physical host. Source: Cloudflare fixes Containers cross-tenant flaw exposing customer data

The flaw represented a significant cloud security concern, as it enabled cross-tenant data exposure through unzeroed storage blocks. Cloudflare's swift remediation addresses a critical gap in container isolation that could have facilitated unauthorized access to sensitive customer information.

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

A vulnerability in Microsoft SharePoint, designated CVE-2026-65660, has been added to CISA's Known Exploited Vulnerabilities catalog and is now being exploited in active attacks. Source: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

The addition to CISA's KEV catalog has established a patching deadline of September 28 for federal agencies, reflecting the severity and active exploitation of this remote code execution vulnerability.

Organizations face a critical patching window today as multiple zero-day and actively exploited vulnerabilities demand immediate attention. Prioritization should focus on Citrix NetScaler environments and Microsoft SharePoint deployments while simultaneously conducting forensic assessments to identify potential compromise before updates are deployed.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CVE8
  • Vulnerability in Citrix NetScaler ADC and Gateway.
  • Vulnerability in Citrix NetScaler ADC and Gateway.
  • Vulnerability in Citrix NetScaler ADC and Gateway.
  • Vulnerability in Citrix NetScaler ADC and Gateway.
  • Critical zero-day vulnerability in Citrix NetScaler ADC and Gateway, actively exploited.
  • Critical zero-day vulnerability in Citrix NetScaler ADC and Gateway, actively exploited.
  • Vulnerability in Citrix NetScaler ADC and Gateway.
  • Vulnerability in Citrix NetScaler ADC and Gateway.