Daily briefing · September 27, 2026

Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention

September 27, 2026 carries an ATTENTION-level verdict driven by two actively exploited Citrix NetScaler ADC and Gateway vulnerabilities confirmed in both CISA KEV and VulnCheck KEV on the day of disclosure. With 117 new CVEs published and 9 rated critical, the session is dominated by the NetScaler pair — one of which was armed with a proof-of-concept exploit on the very same day it was revealed. Defenders operating NetScaler infrastructure must treat today as an emergency patch window.

Today’s brief
  • Two Citrix NetScaler CVEs (CVE-2026-88772 and CVE-2026-88771) are under active exploitation confirmed by both CISA and VulnCheck — patch immediately.
  • CVE-2026-88772 had a working proof-of-concept available on day zero, accelerating attacker weaponization to its fastest possible timeline.
  • A CVSS 10.0 authentication bypass in Seetong NVR devices (CVE-2026-100886) and a remote code execution flaw in hMailServer (CVE-2026-100741) round out the most dangerous new entries.
  • Brazilian organizations are under sustained ransomware pressure — four new victims confirmed recently across manufacturing, healthcare, and agriculture sectors.
9
critical
2
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-88772KEVCVSS 9.5PoCsame dayaffects ADC
Actively exploited (CISA KEV + VulnCheck KEV) critical RCE or DoS in Citrix NetScaler ADC and Gateway, weaponized with a public proof-of-concept on the same day of disclosure — this is the highest-urgency item in today's bulletin and represents a zero-day-speed threat for any unpatched appliance exposed to the internet.
2
CVE-2026-88771KEVCVSS 9.5affects ADC
A companion actively exploited flaw in the same NetScaler product lines allows an unauthenticated attacker to execute arbitrary commands via improper input validation; confirmed in both CISA KEV and VulnCheck KEV on the same day as CVE-2026-88772, suggesting coordinated exploitation of this pair in the wild.
3
CVE-2026-100886CVSS 10PoCaffects T8108
A CVSS 10.0 improper authentication vulnerability in Seetong T8108/T8108P/T8116/T8232 NVR devices exposes their debug service to unauthenticated remote attackers; public exploit code is available and the vendor did not respond to disclosure, meaning no patch timeline exists.
4
CVE-2026-100741CVSS 9.8affects hMailServer
Eval injection in hMailServer 6.0.0–6.3.3 on Windows lets any remote unauthenticated attacker execute arbitrary JScript within the mail server process by crafting a malicious password during standard login flows (SMTP AUTH, POP3, IMAP), granting service-account-level code execution.
5
CVE-2026-100896CVSS 9.4PoCaffects N150RT
An OS command injection in the TOTOLINK N150RT web management interface is remotely exploitable and has a publicly available exploit, making this SOHO router a trivial target for attackers seeking network footholds.
6
CVE-2026-101090CVSS 9.3affects nezha
A Host header injection regression in Nezha 2.2.3's OAuth2 redirect endpoint allows an attacker to hijack authentication flows by manipulating the redirect_uri sent to identity providers, potentially enabling account takeover without credentials.
7
CVE-2026-101084CVSS 9.3affects obot
Obot fails to enforce access control on its /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers using only a server ID — attackers can pivot through stored OAuth credentials to manipulate sensitive backend systems.
8
CVE-2026-101065CVSS 9.3affects obot
The default Obot Docker quickstart configuration listens on all interfaces with authentication disabled, granting every unauthenticated network-reachable party full Owner and Admin privileges — deployments following default documentation are fully exposed.
9
CVE-2026-88773CVSS 9.3affects ADC
HTTP request/response smuggling in Citrix NetScaler ADC and Gateway rounds out the NetScaler triple, enabling request forgery and security control bypass against the same infrastructure targeted by the two KEV entries today.
10
CVE-2026-101045HIGH 8.9affects fleet
Fleet-managed macOS endpoints may execute root-level scripts generated from unescaped Homebrew cask metadata containing shell metacharacters — manifests generated before August 19, 2026 should be audited and regenerated immediately.
Ransomware today

Four new ransomware victims with Brazilian ties have been recently confirmed: Pantaneiro Capas (manufacturing) claimed by arcusmedia, ANP Health (healthcare) by thegentlemen, anery.com.br (agriculture) by lockbit5, and Grupo Caberj (manufacturing) by incransom. Over the past 30 days, thegentlemen has been the most active group targeting Brazil with 8 confirmed victims, followed by lockbit5, emperador, and akira, signaling a sustained multi-group campaign against Brazilian industry. The breadth of sectors — manufacturing, healthcare, agriculture, retail — indicates opportunistic mass targeting rather than a single focused campaign.

Pantaneiro Capas BRarcusmedia · Manufacturing
ANP Health BRthegentlemen · Healthcare
anery.com.br BRlockbit5 · Agriculture and Food Production
Grupo Caberj BRincransom · Manufacturing
thegentlemen 8lockbit5 3emperador 3akira 3Vexy Ransomware 2settra 2
Active groups & APTs

Several threat actor groups are currently tracked as active or recently updated, including ransomhouse, sinobi, spacebears, thegentlemen, funksec, and the North Korean state-sponsored group APT38. While no new confirmed victims are attributed to these actors in the current window, their operational activity and infrastructure updates suggest ongoing reconnaissance or preparation phases. APT38's presence on the active-tracking list warrants attention from financial institutions and cryptocurrency platforms, which are historically primary targets of this Pyongyang-linked group.

Brazil focus

Brazil's threat landscape remains intensely active across multiple sectors, with eight recently confirmed ransomware victims including RECEITA FEDERAL DO BRASIL (government) claimed by emperador, amorsaude.com.br (healthcare) by lockbit5, Metallco (manufacturing) by play, and Javep Chevrolet (retail) by akira. The targeting of a federal tax authority alongside private-sector organizations illustrates that no sector is off-limits for ransomware operators focusing on Brazil. Security teams in Brazilian organizations should treat ransomware readiness — particularly around backup integrity and lateral movement controls — as an immediate operational priority.

Pantaneiro Capasarcusmedia · Manufacturing
ANP Healththegentlemen · Healthcare
anery.com.brlockbit5 · Agriculture and Food Production
Grupo Caberjincransom · Manufacturing
RECEITA FEDERAL DO BRASILemperador · Government & Defense
amorsaude.com.brlockbit5 · Healthcare
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
Today’s recommendation: All organizations running Citrix NetScaler ADC or Gateway must apply the patches released today (versions 14.1-73.37 and 13.1-64.23 and their FIPS/NDcPP equivalents) immediately, as active exploitation with a same-day PoC leaves no safe window for delay; additionally, audit any internet-exposed hMailServer, TOTOLINK, and Seetong deployments for the critical flaws disclosed today.
Given the combination of actively exploited network appliance vulnerabilities and sustained ransomware pressure on multiple sectors, now is the right moment to validate your own external attack surface and confirm which of today's affected products are present in your environment before attackers do it for you.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share