Daily briefing: Sunday, September 27, 2026
Citrix says it has released security updates to fix the flaws and confirmed that two critical NetScaler RCE zero‑day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are being exploited in attacks.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
WatchTowr reports two unpatched Citrix NetScaler RCE flaws were exploited before fixes, while Citrix had not yet published a bulletin or patch. Citrix confirms that CVE-2026-88771 and CVE-2026-88772 are critical zero‑day vulnerabilities being actively exploited and has released security updates. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog, noting they are critical, zero‑day flaws enabling remote code execution.
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation The Hacker News
- Citrix confirms two NetScaler RCE zero-days exploited in attacks BleepingComputer
- Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products Australian Cyber Security Centre
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway CISA
- Critical Vulnerabilities in Citrix NetScaler ADC and Gateway CERT-EU
- Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 Canadian Centre for Cyber Security
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, 2026, describing it as a Microsoft SharePoint Code Injection Vulnerability. The addition gives federal agencies a patching deadline of September 28, 2026.
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
- Cloudflare fixes Containers cross-tenant flaw exposing customer data BleepingComputer
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.