Cyber Pulse: Week 39, 2026

Cyber Pulse · Week 39 · 21–27 Sep 2026

This week in 60 seconds

  • Citrix confirmed on September 27 that CVE-2026-88771 and CVE-2026-88772 have been exploited on unmitigated NetScaler ADC and Gateway appliances.
  • CVE-2026-88771 is an unauthenticated remote-code-execution flaw in the default NetScaler configuration (CVSS 4.0 9.5), added to the CISA KEV catalog on September 27, 2026, with a September 30 due date.
  • This week’s attack tracker has no UAE or GCC incident. The cases listed are global, United States, Germany/Netherlands, and Japan.

Patch now

SeverityCVEProductExploited?Action
CRITCVE-2026-88771Citrix NetScaler ADC/GatewayYes (KEV)Upgrade to 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS, or 13.1.37.279 (FIPS/NDcPP); preserve forensics and run Citrix IOCs before patching where BOD 26-04 applies.
CRITCVE-2026-88772Citrix NetScaler ADC/GatewayYes (KEV)Apply the same fixed builds as CVE-2026-88771 (14.1-73.37 / 13.1-64.23 family).
CRITCVE-2026-93616Check Point Security ManagementYes (KEV)Install R82.20 Security Hotfix or Jumbo Takes R82.10 Take 45 / R82 Take 127 / R81.20 Take 170 / R81.10 Take 192; LivePatch does not remediate this CVE.
CRITCVE-2026-85102Check Point Security Gateway and Spark FirewallYes (KEV)Apply sk1000117 Jumbo/LivePatch and review Mobile Access logs for anomalous certificate-based logins.
CRITCVE-2026-93952Arista VeloCloud OrchestratorYes (KEV)Upgrade to VCO 5.2.3.16+ or 6.4.2.8+; restrict the web UI to trusted networks until 6.1.x / 7.0.x fixes land.

Top stories

1. Citrix confirms two NetScaler RCE zero-days under active exploitation (CVE-2026-88771, CVE-2026-88772)

On September 27, Citrix published security bulletin CTX697096 confirming that CVE-2026-88771 (improper input validation RCE, CVSS v4 9.5, default configuration) and CVE-2026-88772 (memory overflow RCE/DoS when DTLS is enabled, default on VPN vServers) have been exploited on unmitigated NetScaler ADC and Gateway appliances. Fixed builds include 14.1-73.37 and 13.1-64.23 (plus FIPS/NDcPP counterparts); the bulletin also ships six additional NetScaler fixes with no listed workarounds for the two exploited flaws. Source

2. Bitget reports ~$387.5M hot/warm-wallet incident; Mandiant and SlowMist investigating

Bitget detected unauthorized transfers from a portion of its hot and warm wallet infrastructure at approximately 18:31 UTC on September 24 after attackers compromised a backend wallet system to spoof transaction data and trigger authorized-looking payouts; cold wallets and private keys were not reported compromised. The loss estimate was revised to about $387.5 million, the Protection Fund covers the impact so user balances remain intact, and Mandiant plus SlowMist are supporting forensics, tracing, and phased withdrawal restoration from September 28 UTC. Source

3. Check Point confirms active exploitation of Security Gateway VPN RCE and Management path traversal

On September 22, Check Point warned that CVE-2026-85102 (pre-auth RCE via VPN certificate handling, CVSS 9.8) is under active exploitation against Spark customers since September 12, and that CVE-2026-93616 (pre-auth Management web path traversal enabling arbitrary script/Java class load, CVSS 9.8) saw limited zero-day use as early as July 23. Fixes are detailed in sk1000117 and sk1000171; CISA added both CVEs to KEV the same day with a September 25 federal remediation deadline. Source

4. F5 patches critical BIG-IP APM OAuth authorization-server RCE exploited as a zero-day (CVE-2026-94127)

F5 disclosed on September 22 that a heap-based buffer overflow in BIG-IP Access Policy Manager (CVE-2026-94127, CVSS 9.8) enables unauthenticated remote code execution when APM is configured as an OAuth authorization server on a virtual server, and confirmed the flaw has been exploited. Engineering hotfixes cover affected 21.1, 17.5, and 17.1 branches; CISA listed the CVE in KEV on September 22 with a short BOD remediation window. Source

5. Arista urges immediate patching of exploited VeloCloud Orchestrator zero-day (CVE-2026-93952)

Arista Security Advisory 0183 (September 22) discloses a CVSS 10.0 improper input-validation flaw in on-premises VeloCloud Orchestrator that can give remote attackers privileged internal access when Edge certificate-based authentication and web-interface reachability are present, with confirmed active exploitation. Fixed releases include VCO 5.2.3.16+ and 6.4.2.8+; hosted VCO was already patched, and CISA added the CVE to KEV the same day. Source

Threat radar

  • Unauthenticated NetScaler RCE zero-days — Citrix confirmed on September 27 that CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days on unmitigated NetScaler ADC and Gateway deployments. Because patches do not remove pre-patch footholds, preserve evidence, isolate, rotate secrets/certificates, and upgrade to 14.1-73.37 / 13.1-64.23 or later. Source
  • Check Point Spark VPN RCE wave — Exploitation attempts against Spark customers beginning September 12 used VPN/proxy anonymization and certificate subjects such as CN=vpn / CN=vpn-user / CN=vpnuser under O=global, tied to CVE-2026-85102. CVE-2026-93616 Management path traversal saw limited pinpointed attacks from July 23. Source
  • ShinyHunters-linked UNC6240 — A renewed global campaign abuses Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) by URL-encoding a single path character (/%50SEMHUB/ instead of /PSEMHUB/) to evade literal WAF rules. Operators drop JSP web shells, SIDEEYE credential-theft backdoors, NeoGeorg tunnels, and MeshAgent RMM across higher education, technology, healthcare, government, and other sectors. Source

UAE & GCC watch

  • No UAE or GCC incident is in this week’s attack tracker. The listed cases are global, the United States, Germany/Netherlands, and Japan. Earlier regional items stay on Previous Cyber Pulse.
  • AI watch

    • On September 22, 2026, Darktrace announced general availability of Darktrace / SECURE AI, extending its behavioral security model to shadow AI discovery, real-time prompt analysis, policy governance, and AI-agent identity/action monitoring. Integrations cover AWS, Anthropic, Microsoft, and OpenAI platforms. Source
    • Barracuda on September 22, 2026, launched Barracuda AI Data Security on the BarracudaONE platform for visibility, prompt/upload inspection, threat detection aligned to the OWASP LLM Top 10, and audit-ready AI policy enforcement across 1,300+ GenAI tools. Availability is slated for October 2026. Source

    One thing to do this week

    Upgrade unmitigated NetScaler ADC and Gateway appliances to 14.1-73.37 or 13.1-64.23 or later (or the FIPS/NDcPP counterparts 14.1-73.37 FIPS and 13.1.37.279), and preserve evidence, isolate, and rotate secrets and certificates, because patches do not remove pre-patch footholds.

    Compiled from public vendor advisories, CISA KEV and threat-intelligence reporting. For awareness only — verify against vendor guidance before acting. Get this in your inbox every Monday: subscribe to the Monday Brief.

Leave a Comment

Your email address will not be published. Required fields are marked *