- NetScaler RCE vulnerability exploited in attacks
- NetScaler RCE/DoS vulnerability exploited in attacks
ThreatNoir Morning Brief — September 28
Morning Review in IT Security — September 28, 2026
The cybersecurity landscape faces heightened urgency this morning as multiple critical vulnerabilities enter active exploitation phases. Organizations worldwide are confronted with a convergence of zero-day threats affecting widely deployed infrastructure, demanding immediate remediation efforts and forensic assessments before patches are applied.
Citrix Confirms Two NetScaler RCE Zero-Days Exploited in Attacks
Citrix has confirmed that two critical remote code execution vulnerabilities affecting NetScaler products are currently being exploited in active attacks. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, have prompted Citrix to release security updates addressing the flaws. Source: Citrix confirms two NetScaler RCE zero-days exploited in attacks
Both vulnerabilities represent critical threats to organizations relying on NetScaler infrastructure. The confirmation of active exploitation underscores the urgency for administrators to prioritize patching efforts and assess their environments for indicators of compromise.
CISA Issues Alert on Eight Citrix NetScaler Zero-Day Vulnerabilities
The Cybersecurity and Infrastructure Security Agency has amplified Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products. The affected CVEs are CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. Source: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog, confirming that threat actors are actively exploiting these vulnerabilities globally. Both are critical zero-day flaws capable of independently enabling remote code execution. Given the complexity of updating NetScaler appliances and potential downtime requirements, CISA urges organizations to assess exposure and check for indicators of compromise prior to patching. The agency emphasizes the importance of preserving forensic evidence before applying updates, as patches may result in loss of forensic visibility.
Cloudflare Fixes Containers Cross-Tenant Flaw Exposing Customer Data
Cloudflare has remediated a vulnerability in its Containers and Sandboxes services that allowed customers with Workers Paid accounts to recover residual data from other customers' containers on the same physical host. Source: Cloudflare fixes Containers cross-tenant flaw exposing customer data
The flaw represented a significant cloud security concern, as it enabled cross-tenant data exposure through unzeroed storage blocks. Cloudflare's swift remediation addresses a critical gap in container isolation that could have facilitated unauthorized access to sensitive customer information.
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
A vulnerability in Microsoft SharePoint, designated CVE-2026-65660, has been added to CISA's Known Exploited Vulnerabilities catalog and is now being exploited in active attacks. Source: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
The addition to CISA's KEV catalog has established a patching deadline of September 28 for federal agencies, reflecting the severity and active exploitation of this remote code execution vulnerability.
Organizations face a critical patching window today as multiple zero-day and actively exploited vulnerabilities demand immediate attention. Prioritization should focus on Citrix NetScaler environments and Microsoft SharePoint deployments while simultaneously conducting forensic assessments to identify potential compromise before updates are deployed.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Critical zero-day vulnerability in Citrix NetScaler ADC and Gateway, actively exploited.
- Critical zero-day vulnerability in Citrix NetScaler ADC and Gateway, actively exploited.
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Vulnerability in Citrix NetScaler ADC and Gateway.
- Microsoft SharePoint remote code execution vulnerability