Weekly Exploit Roundup 2026-09-29
Weekly Exploit Roundup
Generated 2026-09-29T08:00:11.066827+00:00 (UTC)
- Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
Source: Rapid7 Cybersecurity Blog | Published: 2026-09-28T10:05:00+00:00 | Score: 34.648Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure . CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack complexity for exploiting CVE-2026-88771 is low, meaning reliable RCE is likely against all vulnerable NetScaler appliances regardless of their configuration. This is especially concerning due to the prevalence of NetScaler appliances. CVE-2026-88772 is a memory corruption vulnerability and requires the DTLS feature to be enabled on the appliance. The vendor has indicated that the attack complexity is hi
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Source: The Hacker News | Published: 2026-09-27T07:47:57+00:00 | Score: 27.165Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration.
The bulletin came a day after security firm watchTowr
- Citrix confirms two NetScaler RCE zero-days exploited in attacks
Source: BleepingComputer | Published: 2026-09-27T16:02:37+00:00 | Score: 26.311Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. […]
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Source: The Hacker News | Published: 2026-09-26T11:46:40+00:00 | Score: 24.869Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Source: Alerts | Published: 2026-09-27T12:00:00+00:00 | Score: 23.19CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771 , CVE-2026-88772 , CVE-2026-88773 , CVE-2026-88774 , CVE-2026-88775 , CVE-2026-88776 , CVE-2026-88777 , and CVE-2026-88778 . CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog . Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler deployments can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities. Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Source: The Hacker News | Published: 2026-09-26T08:49:53+00:00 | Score: 22.282The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows –
CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Source: The Hacker News | Published: 2026-09-24T05:36:18+00:00 | Score: 20.457Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.
The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Source: The Hacker News | Published: 2026-09-25T10:14:02+00:00 | Score: 19.309The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash
- CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
Source: Rapid7 Cybersecurity Blog | Published: 2026-09-23T08:43:39+00:00 | Score: 19.236Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic. BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization's network edge, organizations using this configuration should prioritize remediation. The vulnerability affects the data plane and does not expose the BIG-IP control
- When Business Email Compromise Starts Rewriting Reality
Source: Rapid7 Cybersecurity Blog | Published: 2026-09-24T13:00:00+00:00 | Score: 19.077Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars. Business Email Compromise in action: Digital abuse of trust None of this is theoretical for Zimbra. But don’t take my word for it, just ask Russia . CISA keeps putting Zimbra bugs into the Known Explo
End of report.