- Third actively exploited zero-day in Citrix NetScaler products.
- Previously disclosed zero-day that can be accelerated by CVE-2026-88779.
ThreatNoir Morning Brief — October 6
Morning Review in IT Security — October 6, 2026
The cybersecurity landscape continues to shift rapidly as critical vulnerabilities emerge across multiple platforms and organizations face substantial regulatory consequences for data protection failures. Today's briefing covers three active exploitation campaigns affecting enterprise infrastructure, a significant privacy enforcement action, and emerging threats targeting widely deployed server software.
Citrix Discloses Third Actively Exploited NetScaler Zero-Day in Less Than a Week
Citrix has disclosed a third actively exploited zero-day vulnerability affecting NetScaler within a seven-day window, marking an accelerated disclosure timeline compared to previous incidents. The newly identified flaws are tracked as CVE-2026-88771 and CVE-2026-88779. While researchers assess the impact of this latest defect as relatively lower compared to the two preceding zero-days discovered in the same period, the vendor demonstrated notably quicker and more consistent response protocols in addressing the vulnerability. Source: CyberScoop
This rapid succession of critical vulnerabilities in NetScaler underscores the heightened risk facing organizations dependent on Citrix infrastructure and reinforces the urgency of maintaining current patch schedules for this critical platform.
Rejetto HFS Servers Now Actively Scanned for Critical RCE Flaw
Threat actors are conducting active scanning campaigns targeting Rejetto HFS servers to identify instances vulnerable to CVE-2026-61500, a critical remote code execution flaw rooted in weak cryptographic signing keys. The vulnerability enables attackers to forge sessions, facilitate account takeover, and ultimately achieve remote code execution on affected systems. Source: Bleeping Computer
The active scanning indicates that threat actors have already begun reconnaissance and exploitation attempts against exposed Rejetto HFS installations, making immediate patching and network segmentation essential defensive measures.
IQVIA Fined $7.8 Million for Failing to Properly Anonymize Health Data
Italy's Data Protection Authority (GPDP) has imposed a €7 million fine, equivalent to $7.8 million USD, against IQVIA for inadequate data-processing practices that exposed approximately one million patients to potential data exposure and de-anonymization risks. The enforcement action highlights the organization's failure to implement proper anonymization protocols for sensitive health information under its control. Source: Bleeping Computer
This substantial regulatory penalty reflects growing international enforcement of data protection standards and demonstrates that organizations handling sensitive personal health information face significant financial and reputational consequences for inadequate privacy safeguards.
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates addressing a high-severity privilege escalation vulnerability in Microsoft Exchange Server tracked as CVE-2026-96940, which carries a CVSS score of 8.8. The flaw stems from weak authorization controls that permit authenticated attackers to escalate privileges and gain unauthorized access to other users' mailboxes. Source: The Hacker News
The availability of out-of-band patches indicates Microsoft's assessment of the vulnerability's severity and the potential for widespread exploitation within enterprise messaging environments. Organizations operating Exchange Server should prioritize deployment of these updates to prevent unauthorized mailbox access.
Security teams should treat each of these vulnerabilities as high-priority remediation candidates, particularly given the active exploitation campaigns already underway for both Citrix and Rejetto platforms. The regulatory action against IQVIA serves as a reminder that data protection failures extend beyond technical security concerns into substantial compliance and financial liability.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Rejetto HFS weak signing key vulnerability allowing RCE
- Microsoft Exchange Server vulnerability allowing mailbox access