{"date_iso":"2026-09-28","date_human":"Monday, September 28, 2026","generated_utc":"2026-09-28 20:05 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)","link":"https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/","reason":"CVE-2026-88771","category":"Research","sources":["Bleeping Computer","CCCS Alerts & Advisories","CISA Alerts & Advisories","Palo Alto Unit 42","Rapid7 Blog","SecurityWeek","Sophos Threat Research","Tenable Blog","watchTowr Labs"],"coverage":9,"cve_ids":["CVE-2026-88771","CVE-2026-88772","CVE-2026-88773","CVE-2026-88774"],"summary":"God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew\u2026","source":"watchTowr Labs","date_rel":"9h ago","thumbnail":"https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/2026/09/ohlooooook.png","description":"God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that\u2026","related":[{"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild","link":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","source":"Palo Alto Unit 42","date_rel":"5h ago"},{"title":"Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772","link":"https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772","source":"Rapid7 Blog","date_rel":"9h ago"},{"title":"Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug","link":"https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/","source":"SecurityWeek","date_rel":"12h ago"},{"title":"Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation","link":"https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation","source":"Sophos Threat Research","date_rel":"20h ago"},{"title":"AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway \u2013 CVE-2026-88771 and CVE-2026-88772","link":"https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772","source":"CCCS Alerts & Advisories","date_rel":"27 Sep"},{"title":"Citrix confirms two NetScaler RCE zero-days exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/","source":"Bleeping Computer","date_rel":"27 Sep"}]},{"title":"US, UK warn of exploited Citrix NetScaler zero-day bugs","link":"https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug","reason":"Citrix","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Infosecurity Magazine","NCSC UK","The Hacker News","The Record","The Register Security"],"coverage":8,"cve_ids":[],"summary":"Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming\u2026","source":"The Record","date_rel":"3h ago","thumbnail":"http://cms.therecord.media/uploads/marek_piwnicki_667103b28c.jpg","description":"Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.","related":[{"title":"NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities","link":"https://cybersecuritynews.com/citrix-netscaler-0-day-vulnerabilities/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"\u26a1 Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats","link":"https://thehackernews.com/2026/09/weekly-recap-387m-crypto-hack-citrix.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"Citrix security advisory (AV26-965)","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-965","source":"CCCS Alerts & Advisories","date_rel":"7h ago"},{"title":"Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway","link":"https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway","source":"NCSC UK","date_rel":"8h ago"},{"title":"Citrix Patches Critical Zero Days Under Active Exploitation","link":"https://www.infosecurity-magazine.com/news/citrix-patches-critical-zero-days/","source":"Infosecurity Magazine","date_rel":"11h ago"},{"title":"CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally","link":"https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html","source":"The Hacker News","date_rel":"12h ago"}]},{"title":"Microsoft Finds New Malware Used by Hackers to Maintain Secret Access Inside Target Networks","link":"https://cybersecuritynews.com/needymantis-malware-secret-network-access/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside already-breached networks. The malware has appeared in a small number of\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-new-malware-secret-network-access.webp","description":"Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside already-breached networks. The malware has appeared in a small number of highly targeted intrusions involving telecommunications providers , universities, medical nonprofits, intergovernmental bodies, and government contractors. Activity dates to at least October 2025, suggesting operators have quietly used the framework for long-term espionage-oriented access rather than indiscriminate cybercrime. Microsoft new malware secret network access According\u2026","related":[{"title":"Humans Are Reading Copilot Prompts \u2014 And They're Horrified","link":"https://www.404media.co/humans-reading-copilot-prompts-images/","source":"404 Media","date_rel":"6h ago"},{"title":"Microsoft pauses KB5002907 update after Office license deactivations","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/","source":"Bleeping Computer","date_rel":"26 Sep"},{"title":"SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild","link":"https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html","source":"The Hacker News","date_rel":"26 Sep"}]},{"title":"Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M","link":"https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html","reason":"Exchange","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgA8s-yMULxIXnKcHnHw7w1dF9pt58MDYc_-_wfJPo8ifPgGoD0GZcgE408ZdC1GbZvjp2wOOEYrlR8obpFEXZ-KUSjIBXFFb3LcswKfAd3EODISE5hSkU-QplYeZDnK95i0QrJhNZKcKEVgedmkKjAme9PV4vDLV-OY7Bh9KhCINbGuglY49greoPLCJQ/s1600/bitget-hacker.jpg","description":"The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most","related":[{"title":"Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves","link":"https://cybersecuritynews.com/bitget-backend-breach/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist","link":"https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/","source":"Bleeping Computer","date_rel":"10h ago"}]},{"title":"JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources","link":"https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html","reason":"Azure","category":"News","sources":["Bleeping Computer","Dark Reading","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the\u2026","source":"The Hacker News","date_rel":"10h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHYvL1hsEQjB3x7u-jNflFT0QK3a9IEFse8ghWqV9SxkawlFerAn8pzjfYgztccVleVlLzZcDlOSvu7gqJhHP_XLWL1lqZkeIVCifya8Ohinriqk_o-kpzzdtv4x7NinDhQgWbE9B7yJliuJPGZ2x0qh9jRgkWfyNyPexujdTWpLTbfe7MKRVQT1Z3BAQ9/s1600/azure-ai.jpg","description":"The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. \"The destructive operations","related":[{"title":"JadePuffer agentic AI attacks target Azure, destroy cloud resources","link":"https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack","link":"https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack","source":"Dark Reading","date_rel":"4h ago"}]},{"title":"New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS","link":"https://cybersecuritynews.com/new-file-notification-attack/","reason":"Linux","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns inotify, ReadDirectoryChangesW, and FSEvents, which alert\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-File-Notification-Attack.webp","description":"A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns inotify, ReadDirectoryChangesW, and FSEvents, which alert applications when files are changed, into a surveillance mechanism requiring no elevated privileges. The study, \u201cFile Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,\u201d comes from researchers at Graz University of Technology. Rather than exploiting memory corruption, the attack observes legitimate\u2026","related":[{"title":"Linux security advisory (AV26-970)","link":"https://cyber.gc.ca/en/alerts-advisories/linux-security-advisory-av26-970","source":"CCCS Alerts & Advisories","date_rel":"20m ago"},{"title":"SUSE Linux security advisory (AV26-968)","link":"https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-968","source":"CCCS Alerts & Advisories","date_rel":"1h ago"}]},{"title":"RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims","link":"https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html","reason":"Android","category":"News","sources":["GitHub Security Lab","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvGUhf2JsmovUtvjDk66AKULOtbtRwTqgcT_6lr5l8AEuwc-12IQTTWfvjKCYEn6-wwc4ZLDWAWh6Edv3-XcPDL1HHPFwRkwY1Nc_BUItyEO8iCXBDKEitrgYapLi__gpKnYqtFNm1M2c4tGiY3qrS_CgRG5ZF5qnqVUv4Gx9Pqk_cPz4N05KVwUNgTcw/s1600/gemini-malware.jpg","description":"RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,","related":[{"title":"How we found 24 Android vulnerabilities using our open source AI security agent","link":"https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/","source":"GitHub Security Lab","date_rel":"1h ago"}]},{"title":"ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns","link":"https://therecord.media/shinyhunters-cyberattacks-oracle-mandiant","reason":"Oracle","category":"News","sources":["Cyber Security News","The Record"],"coverage":2,"cve_ids":[],"summary":"A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI\u2019s jobs site.","source":"The Record","date_rel":"35m ago","thumbnail":"http://cms.therecord.media/uploads/Oracle_f966bc5532.jpg","description":"","related":[{"title":"ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells","link":"https://cybersecuritynews.com/shinyhunters-bypasses/","source":"Cyber Security News","date_rel":"6h ago"}]},{"title":"Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells","link":"https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html","reason":"Google","category":"News","sources":["Dark Reading","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the\u2026","source":"The Hacker News","date_rel":"26 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYN2VWIT2g8mQkV0GeZWzYErKcubb0-baI8J__2nmdElucECc7HrLkdPsR1dz93qjMBI5sr_dL8yPWHf2bwWCBXa3YfutHAeJ-70UCSMuJrHhyOB3RO4OkuDjuw7gxRLXUnK-CeK9jZO0uOJRy-N3w-rV7uZ4t1FnFIWNjEsKtSYQINUvPX31mKzV_5Ert/s1600/oracle-flaw.jpg","description":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day","related":[{"title":"Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions","link":"https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions","source":"Dark Reading","date_rel":"3h ago"}]},{"title":"CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/microsoft-sharepoint-code-injection/","reason":"CVE-2026-65660","category":"News","sources":["Cyber Security News","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-65660"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660, to its KEV Catalog after evidence showed the flaw was being\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-SharePoint-Code-Injection.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660, to its KEV Catalog after evidence showed the flaw was being exploited in attacks. The vulnerability affects Microsoft SharePoint and could enable an authorized attacker to execute code remotely over a network, creating a significant risk for organizations that rely on SharePoint for document management, collaboration, and internal business workflows. CVE-2026-65660 is classified as CWE-94, or Improper Control of Generation of Code, commonly\u2026","related":[{"title":"Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks","link":"https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/","source":"SecurityWeek","date_rel":"27 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-100886","vendor":"Seetong","product":"T8108","severity":"CRITICAL","score":10.0,"description":"A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack m\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100886"},{"id":"CVE-2026-101000","vendor":"Netcore","product":"NBR100V2","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101000"},{"id":"CVE-2026-101001","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":10.0,"description":"A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to o\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101001"},{"id":"CVE-2026-101039","vendor":"FAST","product":"FAC1900R","severity":"CRITICAL","score":10.0,"description":"A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101039"},{"id":"CVE-2026-100896","vendor":"TOTOLINK","product":"N150RT","severity":"CRITICAL","score":9.9,"description":"A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes o\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100896"},{"id":"CVE-2026-101002","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os c\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101002"},{"id":"CVE-2026-82377","vendor":"Apache","product":"Apache Roller","severity":"CRITICAL","score":9.9,"description":"Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the cal\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82377"},{"id":"CVE-2026-101037","vendor":"FAST","product":"FAC1200R","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remo\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101037"},{"id":"CVE-2026-101038","vendor":"FAST","product":"FAC1200R","severity":"CRITICAL","score":9.9,"description":"A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-101038"},{"id":"CVE-2026-88771","vendor":"Citrix","product":"Netscaler Application Delivery Controller","severity":"CRITICAL","score":9.8,"description":"Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1\u2026","cwe":"CWE-20","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-09-30","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-88771"}],"vendor_spikes":[{"vendor":"Apache","count":20,"critical_count":3},{"vendor":"Trusted Domain Project","count":9,"critical_count":0},{"vendor":"Citrix","count":8,"critical_count":1},{"vendor":"mathurvishal","count":8,"critical_count":0},{"vendor":"WordPress","count":8,"critical_count":0},{"vendor":"Red Hat","count":6,"critical_count":0},{"vendor":"nezhahq","count":6,"critical_count":1},{"vendor":"x.org","count":6,"critical_count":0},{"vendor":"universal-tool-calling-protocol","count":5,"critical_count":0},{"vendor":"obot-platform","count":5,"critical_count":2}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":173,"has_news_data":true,"has_cve_data":true}