BoletimSec•September 29, 2026•🇵🇹Translated from Portuguese

CISA Adds Two Critical Citrix NetScaler Flaws to Known Exploited Vulnerabilities Catalog

The CISA has added two critical vulnerabilities in Citrix NetScaler products to its Known Exploited Vulnerabilities catalog after reports of active exploitation on a global scale. The agency set a deadline of September 30 for U.S. federal agencies to apply the necessary fixes.

The two vulnerabilities are CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale. Citrix released the corrected versions on September 27, coinciding with the CISA inclusion.

CVE-2026-88771 results from inadequate input validation and permits execution of arbitrary commands without authentication. It impacts all default installations of NetScaler ADC and NetScaler Gateway.

CVE-2026-88772 originates from a flaw in memory buffer boundary controls, enabling remote code execution or denial of service. Exploitation requires DTLS, which is enabled by default on VPN virtual servers.

Vulnerable versions are 14.1-73.32, 13.1-63.21 and earlier. Patches are available starting from 14.1-73.37 and 13.1-64.23, with equivalent numbers for FIPS variants.

The exploitation was identified by watchTowr on September 26, and Citrix confirmed the following day that attacks against unmitigated installations had already been observed. No workaround has been provided, and the guidance is to update to the fixed releases.

Applying the patch does not indicate whether a device has already been compromised. Organizations should preserve evidence, isolate the appliance, revoke credentials, investigate connected systems, rebuild with the latest firmware, and rotate passwords and encryption keys.

Related articles

Habr•Vulnerabilities & Exploits

cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology

CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities based on the Urgent Patch Score (UPS) framework that tracks signals such as exploit publication and confirmed attacks. The index addresses the growing gap between accelerated vulnerability discovery powered by AI and the slower pace of patching, testing, and deployment in real environments. It incorporates timelines from sources including Anthropic reports on AI-assisted campaigns GTG-50014 and GTG-50029, the rust-in-peace framework, Microsoft Exchange Server Subscription Edition delays, and Oracle’s record 1,434 CVE fixes. UPS defines progressive phases from Radar to Emergency/IR, allowing teams to link specific events like PoC releases or CISA KEV additions to concrete actions under resource constraints. Research using 2025 CISA KEV data shows that early signals enable 35–53% of patches to be completed before official exploitation confirmation. The public version displays only Urgent Patch and Emergency stages with event histories, while full data and API access are available to CyberOK customers.

Security NEXT•Vulnerabilities & Exploits

Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw

WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.

AntiMalware•Vulnerabilities & Exploits

Apple Patches Zero-Day CVE-2026-86950 in CoreGraphics Exploited in Targeted iOS Attacks

Apple has released emergency security updates for iPhone, iPad, and multiple macOS versions to address a zero-day vulnerability tracked as CVE-2026-86950. The flaw resides in the CoreGraphics framework responsible for rendering images, text, and 2D graphics. It was discovered by Meta Product Security and confirmed to have been used in sophisticated, targeted attacks against specific iOS users. The vulnerability is an out-of-bounds write that could allow arbitrary code execution when processing a specially crafted file. Apple states the attacks were highly selective rather than widespread. Patches are included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. An erroneous CVE identifier, CVE-2026-20700, appeared in some early reports.

Security NEXT•Vulnerabilities & Exploits

Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks

Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.