Daily briefing: Sunday, September 27, 2026

Citrix says it has released security updates to fix the flaws and confirmed that two critical NetScaler RCE zero‑day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are being exploited in attacks.

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

WatchTowr reports two unpatched Citrix NetScaler RCE flaws were exploited before fixes, while Citrix had not yet published a bulletin or patch. Citrix confirms that CVE-2026-88771 and CVE-2026-88772 are critical zero‑day vulnerabilities being actively exploited and has released security updates. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog, noting they are critical, zero‑day flaws enabling remote code execution.

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, 2026, describing it as a Microsoft SharePoint Code Injection Vulnerability. The addition gives federal agencies a patching deadline of September 28, 2026.

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.