Security NEXT•October 1, 2026•🇯🇵Translated from Japanese

Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws

The Apache WSS4J library, which enables the application of WS-Security to SOAP messages in Java environments, has been found to contain multiple vulnerabilities. A coordinated update addressing all seven issues is now available.

On September 30, 2026, the development team published several security advisories confirming the fixes. Three of the vulnerabilities were rated Important: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616.

CVE-2026-88920 is an authentication bypass flaw in the DOM security processor. An attacker can insert a controlled key into a crafted unsigned sender-vouches SAML assertion, allowing forged authenticated SOAP messages to be accepted.

CVE-2026-89238 involves a processing issue with encryption headers. Attackers can supply plaintext elements that are incorrectly treated as decrypted headers, undermining confidentiality protections and bypassing defined security policies.

The remaining four vulnerabilities, tracked as CVE-2026-85532, CVE-2026-87830, CVE-2026-92121, and CVE-2026-92899, were also resolved in the same release. Users are advised to apply the latest patched versions of Apache WSS4J immediately.

Related articles

Security NEXT•Vulnerabilities & Exploits

US Authorities Warn of Active Exploitation of Apple CoreGraphics and Cisco SD-WAN Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two newly identified vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-86950 affects Apple iOS, iPadOS, and macOS through a flaw in the CoreGraphics framework that allows out-of-bounds memory writes and potential arbitrary code execution. CVE-2026-76504 impacts Cisco Catalyst SD-WAN Manager, enabling unauthenticated attackers to gain administrative access due to improper URI encoding handling in the API. Federal agencies must remediate both issues within three days of their respective catalog additions. CISA also requires organizations to check for signs of compromise in addition to applying patches. The alerts highlight ongoing risks to widely deployed Apple operating systems and enterprise SD-WAN infrastructure.

Security NEXT•Vulnerabilities & Exploits

Cisco Patches Critical Zero-Day Authentication Bypass in Catalyst SD-WAN Manager

Cisco Systems has released security updates to address a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows attackers to bypass authentication and gain remote administrator access. The flaw, tracked as CVE-2026-76504, stems from improper URI encoding handling in HTTP requests targeting specific APIs. With a CVSS v3.1 base score of 9.8, the issue is rated Critical and has already been exploited in real-world attacks confirmed by Cisco in September 2026. The company published its security advisory on September 30, 2026, and strongly recommends immediate updates to the fixed releases. Organizations are also advised to restrict API access to trusted sources while applying the patches.

Hispasec•Vulnerabilities & Exploits

Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement

Two critical zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild to achieve unauthenticated remote code execution. Attackers deploy password-protected PHP web shells such as WHIPSHOT and use the Python-based SLAPSHOT tunneling tool for lateral movement inside targeted networks. The flaws affect NetScaler ADC and NetScaler Gateway appliances with default configurations, and one requires DTLS enabled on VPN vServers. Citrix has released patches for versions 13.1-64.23 and 14.1-73.37, while CISA added the issues to its KEV catalog with a September 30, 2026 remediation deadline for U.S. federal agencies. Organizations are advised to hunt for indicators including modified httpd.conf entries, anomalous setuid permissions on /bin/sh, and suspicious files in /var/netscaler/logon/LogonPoint/custom before applying updates.

Security NEXT•Vulnerabilities & Exploits

Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ

SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.