Citrix Patches Critical NetScaler RCE Flaw (CVE-2026-107406). A CVSS 9.5 memory overflow vulnerability in NetScaler ADC and Gateway can lead to remote code execution or denial-of-service when the appliance is configured as a SAML IdP or SP. Citrix reports no active exploitation yet, but given the history of NetScaler flaws being weaponized within days of disclosure, immediate patching to the latest supported version is non-negotiable. Learn more
AhsayCBS Backup Flaws CVE-2026-105133 and CVE-2026-105134 Exploited in the Wild. Attackers are chaining two unpatched authentication bypass and OS command injection vulnerabilities in AhsayCBS to deploy webshells and XMRig cryptocurrency miners disguised as Microsoft Edge processes. All versions up to 10.3.4 are affected; Huntress MDR recommends restricting access to the management interface immediately until a vendor patch is available.
Max-Severity SonicWall SMA1000 Flaw Under Active Exploitation. CVE-2026-102255 affects the SMA1000 Appliance WorkPlace interface, allowing unauthenticated remote attackers to issue requests on behalf of the appliance. Exploitation began shortly after patch release, continuing SonicWall's pattern of rapid post-patch weaponization that CISA has previously linked to ransomware operators.
Atlassian Data Center CVE-2026-21589 Exploited Within Hours of PoC Release. The CVSS 9.3 flaw in Atlassian self-hosted Data Center products allows unauthenticated file access and, when integrated with Jira and Crowd, can expose plaintext Crowd admin credentials. Exploitation attempts were logged from multiple countries within hours of technical details being published. Learn more
Key Takeaway
Treat PoC publication as a zero-hour countdown: patch NetScaler, SonicWall SMA1000, AhsayCBS, and Atlassian Data Center products this week or implement compensating controls before attackers do.
