Security NEXT•October 1, 2026•🇯🇵Translated from Japanese

US Authorities Warn of Active Exploitation of Apple CoreGraphics and Cisco SD-WAN Vulnerabilities

US authorities have issued warnings about actively exploited vulnerabilities in Apple products and Cisco Catalyst SD-WAN Manager. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities catalog, requiring rapid remediation by federal agencies.

CVE-2026-86950 was added on September 29, 2026. The vulnerability resides in the CoreGraphics framework used by iOS, iPadOS, and macOS. It permits out-of-bounds memory writes that can lead to arbitrary code execution when successfully exploited.

CVE-2026-76504 was added the following day. The issue affects the API of Cisco Catalyst SD-WAN Manager and stems from improper URI encoding processing. Attackers can bypass authentication and obtain administrative privileges without valid credentials.

Federal agencies must complete remediation and compromise assessments by October 2 for the Apple flaw and October 3 for the Cisco flaw. CISA emphasizes both patching and investigation of potential prior intrusions.

Related articles

Security NEXT•Vulnerabilities & Exploits

Cisco Patches Critical Zero-Day Authentication Bypass in Catalyst SD-WAN Manager

Cisco Systems has released security updates to address a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows attackers to bypass authentication and gain remote administrator access. The flaw, tracked as CVE-2026-76504, stems from improper URI encoding handling in HTTP requests targeting specific APIs. With a CVSS v3.1 base score of 9.8, the issue is rated Critical and has already been exploited in real-world attacks confirmed by Cisco in September 2026. The company published its security advisory on September 30, 2026, and strongly recommends immediate updates to the fixed releases. Organizations are also advised to restrict API access to trusted sources while applying the patches.

Hispasec•Vulnerabilities & Exploits

Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement

Two critical zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild to achieve unauthenticated remote code execution. Attackers deploy password-protected PHP web shells such as WHIPSHOT and use the Python-based SLAPSHOT tunneling tool for lateral movement inside targeted networks. The flaws affect NetScaler ADC and NetScaler Gateway appliances with default configurations, and one requires DTLS enabled on VPN vServers. Citrix has released patches for versions 13.1-64.23 and 14.1-73.37, while CISA added the issues to its KEV catalog with a September 30, 2026 remediation deadline for U.S. federal agencies. Organizations are advised to hunt for indicators including modified httpd.conf entries, anomalous setuid permissions on /bin/sh, and suspicious files in /var/netscaler/logon/LogonPoint/custom before applying updates.

Security NEXT•Vulnerabilities & Exploits

Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ

SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.

BoletimSec•Vulnerabilities & Exploits

WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution

WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.