The Hot Drop for 10-01-2026

ShinyHunters just breached the FBI and Nissan with a PeopleSoft zero-day. Meanwhile, Apple patched a CoreGraphics flaw used against journalists, while Citrix NetScaler zero-days are already active globally, forcing a Sept 30 deadline for

Since the last show: 5 new · 5 developing · 5 dropped · 33% overlap with the previous show

Contents

  1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan
  2. Apple patches CoreGraphics zero-day exploited in targeted attacks
  3. Citrix NetScaler Zero-Days Exploited Globally: CISA Mandates Patching by Sept 30
  4. Citrix NetScaler Zero-Day Exploited for Root Access
  5. Zimbra CVE-2026-73570 Exploitation
  6. CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double
  7. Cisco patches actively exploited zero-day in Catalyst SD-WAN Controller
  8. CISA Mandates Patch for Critical Cisco SD-WAN Auth Bypass
  9. New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines
  10. OWASP ModSecurity WAF Bypass Flaws Disclosed

1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan (Lead)

Event now covered by 2 outlets (was 1); 1 new indicator(s) observed

What changed

ShinyHunters is actively exploiting a critical zero-day in Oracle PeopleSoft, compromising over one hundred organizations including the FBI and Nissan Americas. The group, tracked as UNC6240, leveraged CVE-2026-35273, an unauthenticated remote code execution flaw in PeopleTools versions 8.61 and 8.62. This campaign ran from May 27 to June 9, 2026. While the FBI’s job portal remains offline, Nissan confirmed the exposure of Social Security numbers and banking details for employees in the US, Canada, Mexico, and Brazil. ShinyHunters has launched a new wave of attacks against agriculture, government, and healthcare organizations, claiming to have compromised personal information of FBI employees. Google’s Mandiant and Threat Intelligence Group report that the group used a new technique to target PeopleSoft servers that had not applied security updates. The FBI confirmed it is investigating ShinyHunters’ claim of having compromised personal information of its employees. ShinyHunters leveraged an unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach portals. Attackers deployed web shells by targeting exposed Environment Management Hub endpoints, using URL-encoding to bypass WAF protections. Reports are consistent on the vulnerability and the WAF bypass technique, though some outlets differ on whether the initial target was strictly higher education or a broader mix of sectors. You need to check if your PeopleSoft instances are exposed and verify that WAF rules account for percent-encoded or mixed-case variants of the PSEMHUB endpoint. Watch for connections to attacker infrastructure domains like azurenetfiles[.]net or IPs 142[.]11[.]200[.]186 and 162[.]219[.]30[.]165. The lead sheet details the full IOC set and the specific WAF evasion patterns.

How it works

The weakness, rated a CVSS 9.8, requires no authentication or network interaction to succeed, meaning any HTTP-accessible instance becomes an immediate takeover target. Specifically, this enables immediate takeover of the Oracle Concurrent Processing service without any prior access precondition. UNC6240 modified its exploit to bypass web application firewall rules blocking the vulnerable Environment Management Hub endpoint. Threat actors used percent-encoded, mixed-case, or otherwise non-normalized variants of the /PSEMHUB/ path to evade detection. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest, with the University of Nottingham being one of the first confirmed victims.

What to do

The FBI is investigating ShinyHunters’ claim of compromising employee personal information, elevating the threat from a corporate breach to a national security incident. Unlike the other CVE in this set, this specific flaw targets the Updates Environment Management subsystem, forcing operators to isolate PeopleSoft 8.61 and 8.62 immediately while waiting for the official fix. While the broader event includes CVE-2026-35273, this specific flaw stands out because its unauthenticated nature means defenders must immediately isolate affected Oracle E-Business Suite instances to prevent remote takeover. Because UNC6240 modified its exploit to bypass WAF rules by using percent-encoded or mixed-case variants of the PSEMHUB endpoint, standard signature-based filtering is no longer sufficient to protect exposed PeopleSoft servers. Apply the Oracle Emergency Security Update immediately to remediate CVE-2026-35273 in PeopleSoft PeopleTools versions 8.61 and 8.62, as the advisory confirms the vulnerability is remotely exploitable without authentication. Update WAF configurations to explicitly block non-normalized, percent-encoded, and mixed-case variants of the /PSEMHUB/ endpoint to prevent the specific bypass technique used by UNC6240.

Limits and watch

Reports conflict on whether the initial target set was strictly higher education or a broader mix of agriculture, government, and healthcare, which complicates the assessment of which sectors are currently at highest risk. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment for persistent access.

Vulnerabilities

  • CVE-2025-61882 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
  • CVE-2026-35273 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).

Techniques

  • AML.T0000 Search Open Technical Databases (Reconnaissance)
  • AML.T0006 Active Scanning (Reconnaissance)
  • AML.T0049 Exploit Public-Facing Application (Initial Access)
  • AML.T0050 Command and Scripting Interpreter (Execution)
  • AML.T0055 Unsecured Credentials (Credential Access)
  • AML.T0072 Reverse Shell (Command And Control)
  • T1005 Data from Local System (Collection)
  • T1016 System Network Configuration Discovery (Discovery)
  • T1018 Remote System Discovery (Discovery)
  • T1027 Obfuscated Files or Information (Stealth)
  • and 10 more

Named actors and malware

  • ShinyHunters (actor)
  • Neo-reGeorg (malware)
  • Umbreon (malware)
  • TeamPCP (actor)
  • Umbreon. (malware)

Indicators

  • 23 indicators on file

Coverage


2. Apple patches CoreGraphics zero-day exploited in targeted attacks (Segment)

5 new indicator(s) observed

What changed

On September twenty-eighth, Apple pushed emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS to patch CVE-2026-86950, a zero-day vulnerability in the CoreGraphics framework. Reported by Meta Product Security, this out-of-bounds write flaw allows arbitrary code execution when the system processes maliciously crafted files. CISA has added the bug to its Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. Although researchers at Califio have published a proof-of-concept, the technical details remain sparse. If you see a device that hasn’t updated after the September twenty-eighth release, isolate it now. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27.

How it works

The vulnerability resides in the CoreGraphics component, where an out-of-bounds write occurs during the processing of maliciously crafted files, potentially PDFs with embedded fonts. This memory safety issue allows an attacker to execute arbitrary code on the device, a capability that Apple addressed in the patch by implementing improved bounds checking. The attacker leveraged this weakness by processing a maliciously crafted file to trigger the improved bounds checking failure, resulting in arbitrary code execution with a CVSS score of 8.8. The vulnerability stems from a memory corruption issue where an attacker with write capability can execute arbitrary code by exploiting improved state management flaws. The patch applies to iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later.

What to do

The CVSS score of 7.8 indicates high severity, yet attackers need only minimal privileges to trigger the exploit on affected Apple platforms. Because the flaw enables arbitrary code execution when processing malicious files, any unpatched device in your fleet represents a direct entry point for the sophisticated targeted attacks Apple has already confirmed. Apple declined to provide further details regarding the victims or the nature of the attacks, and researchers have not disclosed the full exploit chain. This uncertainty means we cannot confirm the exact delivery vector, though the PoC suggests WhatsApp could serve as a vector for the malicious file. The framework-to-behavior connection here is that T1203, Exploitation for Client Execution, relies on the user action of opening the file, which aligns with T1204.002, Malicious File. The most useful investigation focus is enabling T1203 mitigation option 1, Application Isolation and Sandboxing, and T1203 mitigation option 2, Exploit Protection, to detect and block conditions indicative of software exploits. Additionally, enable T1204.002 mitigation option 1, Behavior Prevention on Endpoint, and T1204.002 mitigation option 2, Execution Prevention, to block unauthorized code execution and monitor for anomalous patterns indicative of the exploit. The watch item is a signal of unpatched iOS devices before iOS 27 that have processed PDF files recently, as this is the only concrete signal supported by the evidence. Update all managed devices to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 immediately to close the CoreGraphics vulnerability and stop arbitrary code execution. Isolate any device that has not yet received the September twenty-eighth emergency patch, as these systems remain exposed to the specific targeted attack vectors described in the advisory.

Limits and watch

While the out-of-bounds write in CoreGraphics is confirmed, the specific file types and delivery mechanisms used in the targeted attacks remain sparse in the available technical details. The scope of exploitation is currently limited to specific targeted individuals on iOS versions prior to iOS 27, meaning the full extent of compromise across your broader user base is not yet established. Watch for client application crashes or abnormal exits in CoreGraphics-dependent processes, as these indicate potential exploitation attempts against the unpatched vulnerability.

Vulnerabilities

  • CVE-2026-86950 — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.
  • CVE-2026-20700 — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.

Techniques

  • T1203 Exploitation for Client Execution (Execution)
  • T1204.002 Malicious File (Execution)
  • T1213.005 Messaging Applications (Collection)

Indicators

  • 6 indicators on file

Coverage


3. Citrix NetScaler Zero-Days Exploited Globally: CISA Mandates Patching by Sept 30 (Segment)

4 new indicator(s) observed; 5 new attacker infrastructure indicator(s)

What changed

On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway products, including two critical remote code execution flaws that were already being actively exploited as zero-days. Specifically, CVE-2026-88771 and CVE-2026-88772 allow unauthenticated remote code execution. GreyNoise and Mandiant intelligence suggests exploitation began as early as September 3, with confirmed detections on September 24 targeting government and financial sectors in North America and Europe. Attackers are gaining root access to deploy web shells like WHIPSHOT and SLAPSHOT, steal credentials, and move laterally. Palo Alto Networks counts over fifty thousand exposed instances globally. CISA added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. The CISA catalog mandates federal patching by September 30, but you should treat this as a global emergency. If you have unpatched NetScaler devices, isolate them from the internet immediately. Advanced persistent threat groups and ransomware affiliates have confirmed exploitation of Citrix NetScaler ADC, with the Dutch National Cyber Security Center issuing warnings to IT suppliers about the active attacks. The vulnerabilities affect client authentication by requiring only network access and zero valid credentials, meaning the lack of a user account provides no protection against these remote code execution vectors. Look for the specific attacker infrastructure IPs 45[.]141[.]21[.]130 and 64[.]94[.]85[.]67 in your logs.

How it works

Threat actors are actively leveraging two critical remote code execution vulnerabilities to gain initial footholds in Citrix NetScaler ADC and Gateway appliances. An unauthenticated remote attacker can exploit the flaw to execute arbitrary commands on an affected appliance, bypassing standard security controls without needing prior access. Specifically, attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. This improper input validation allows attackers to inject malicious content that bypasses zone controls and executes scripting code on the appliance. Additionally, Citrix NetScaler ADC before version 14.1-73.37 mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests. This weakness allows attackers to bypass feature restrictions by manipulating the request URL structure. The underlying weakness allows an attacker to read past buffer boundaries, potentially exposing sensitive data or crashing the system. An attacker triggers this overflow to cause denial of service, distinct from the other nine CVEs in this set. Zero-day vulnerabilities affect Citrix NetScaler application delivery controllers, allowing attackers to compromise the infrastructure that manages network traffic and access. Because the flaws require no valid credentials, any internet-facing NetScaler deployment is exposed to immediate compromise, regardless of user account security policies. Today, NetScaler ADC 14.1 and Gateway 14.1 remain exposed to CVE-2026-19490 until version 73.32. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 face memory overflow risks today. Citrix NetScaler ADC before version 14.1-73.37 faces a feature policy bypass via improper HTTP URL expression. This weakness in the load balancer lets adversaries bypass security boundaries by injecting malicious traffic into back-end servers. NetScaler Gateway 14.1 users face high-impact memory overread via insufficient input validation when acting as an RDP Proxy. This unauthenticated remote code execution grants full system control, enabling denial of service through resource exhaustion. This command injection flaw allows unauthenticated attackers to execute commands, causing crashes or resource exhaustion on affected Citrix devices.

What to do

Threat actors are actively exploiting unauthenticated command injection in Citrix NetScaler ADC and Gateway versions before 14.1-73.37 to achieve remote code execution with a CVSS score of 8.1. Because these flaws require zero valid credentials, your existing user account controls offer no protection against this unauthenticated remote code execution currently targeting your NetScaler appliances. Active exploitation by APT and ransomware groups means any unpatched device is already a potential entry point for root-level access and lateral movement. Unlike the ten other CVEs in this set, this specific overread in the Gateway product offers a direct path to sensitive information exposure, distinguishing it from the other nine CVEs in this event. Operators must verify their NetScaler Gateway and ADC versions immediately to prevent this specific bypass. Patching alone may not resolve lateral movement if threat actors have already deployed persistent backdoors, so apply framework mitigation options by enabling application isolation and sandboxing to restrict code execution to controlled environments while disabling unnecessary features to reduce the attack surface. You must verify system compromise before upgrading, as attackers are known to hide infrastructure behind fake stylesheet addresses and modify setuid bits, which means your detection focus should be on observing post-exploitation payloads that create superuser accounts and mapping web shells to CSS-Like URLs rather than relying solely on generic vulnerability scans. The watch item is the specific signal of log poisoning attempts to exfiltrate data to Hetzner servers, which confirms that the attacker’s goal is data theft rather than just initial access. Patch NetScaler ADC and Gateway immediately to close the remote code execution and denial-of-service vectors in CVE-2026-88771 and CVE-2026-88772. Isolate any devices that cannot be patched immediately from the internet to prevent unauthenticated attackers from executing arbitrary commands. Patch versions before 14.1-73.37 to stop the privilege elevation and resource exhaustion caused by improper input validation. Patch NetScaler Gateway before 13.1-64.23 to address the input validation flaw detectable by static analysis tools. Patch immediately to stop the privilege escalation, as no other mitigation exists for this critical remote code execution issue. Patch affected appliances immediately to stop active exploitation chains in the Citrix NetScaler family. Patch immediately or isolate affected appliances, as the CVSS 9.8 score confirms high severity with no authentication required.

Limits and watch

Static analysis detects the improper input validation, but no specific patch release date is confirmed for today’s timeline.

Vulnerabilities

  • CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2025-5777 — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
  • CVE-2026-19490 — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
  • CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88778 — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

Techniques

  • AML.T0072 Reverse Shell (Command And Control)
  • T1021.001 Remote Desktop Protocol (Lateral Movement)
  • T1021.007 Cloud Services (Lateral Movement)
  • T1087.001 Local Account (Discovery)
  • T1133 External Remote Services (Persistence)
  • T1136.001 Local Account (Persistence)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1202 Indirect Command Execution (Stealth)
  • T1203 Exploitation for Client Execution (Execution)
  • T1204.002 Malicious File (Execution)
  • and 7 more

Indicators

  • 23 indicators on file

Coverage


4. Citrix NetScaler Zero-Day Exploited for Root Access (Segment)

3 new indicator(s) observed

What changed

Mandiant and Google Threat Intelligence Group confirmed active exploitation of two critical Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, by unknown actors since early September. Attackers targeted NetScaler ADC and Gateway appliances across North America and Europe. GreyNoise observed pre-disclosure attempts from IPs 149[.]104[.]78[.]141 and 143[.]198[.]7[.]94, with a surge in mass exploitation noted on September 28. The mechanism is a DTLS memory overflow that bypasses authentication entirely, granting root access on the underlying FreeBSD systems. Once inside, the threat actor deployed custom malware, specifically the WHIPSHOT PHP web shell and SLAPSHOT Python tunneler, to establish persistence and conduct internal reconnaissance. The threat actor leveraged lightweight installer web shells to assert the setuid bit on the /bin/sh executable to establish persistent root-level execution. The threat actor conducted credential theft on the compromised NetScaler gateways. Look for modified Apache configurations and setuid bits on /bin/sh, which indicate persistent root-level execution.

How it works

Citrix NetScaler ADC versions before 14.1-73.37 allow unauthenticated attackers to execute arbitrary commands via improper input validation. Attackers need no authentication to trigger the flaw, exploiting a high-severity weakness in the NetScaler stack. The weakness is CWE-20, allowing Cross Zone Scripting where a zone-aware browser loads malicious content to bypass security controls. An attacker exploits this weakness to trigger Cross Zone Scripting or Client-side Injection-induced Buffer Overflow, crashing the device. Citrix NetScaler ADC and Gateway before 14.1-73.37 mishandle HTTP smuggling, letting attackers inject unauthorized requests. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 allow feature policy bypass via improper HTTP URL expression. This overflow within the eight-part event set allows attackers to cause unpredictable behavior without requiring authentication or network access. An attacker triggers this overflow by sending crafted traffic, which the ADC misinterprets as a valid request. An attacker triggers this overflow by sending malformed requests to the ADC or Gateway, exploiting the underlying memory handling flaw. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 and 13.1-64.23 face remote code execution or denial of service. This flaw targets specific Citrix versions, enabling secret injection of malicious requests to back-end servers. This weakness, part of a set of eight Citrix flaws, enables attackers to bypass access controls on affected NetScaler products. Corruption affects organizations in North America and Europe in the government, financial services, education, legal and professional services sectors. The threat actor has deployed multiple PHP web shells and a tunneler malware to proxy traffic into the victim organization’s network facilitating internal reconnaissance, lateral movement and credential harvesting.

What to do

This eighth Citrix vulnerability, rated 9.8, allows immediate high-impact compromise without authentication, making it a critical priority for operators managing ADC infrastructure. Unlike other CVE-2026-8877x flaws, this NetScaler weakness directly impacts traffic handling without complex prerequisites, causing specific ADC versions to crash under load. Compromised gateways in North America and Europe now serve as launchpads for internal reconnaissance, exposing government, financial, and legal sectors to deep network infiltration. The deployment of WHIPSHOT web shells and SLAPSHOT tunnelers confirms that initial access has transitioned into persistent root-level control, enabling credential harvesting and traffic proxying. Operators must patch affected Citrix releases immediately to block this request smuggling attack vector. Apply Citrix patches to reach version 14.1-73.37 or 13.1-64.23 on all NetScaler ADC and Gateway instances to close the unauthenticated remote code execution vector identified in CVE-2026-88771. Verify NetScaler Gateway and ADC instances are patched before 14.1-73.37 to prevent resource exhaustion and data theft. Check NetScaler versions immediately against the CISA catalog to prevent exploitation of this active threat. Patch affected NetScaler ADC and Gateway systems immediately to prevent the high-impact CVSS 9.8 exploitation. Isolate zone-aware browsers and apply LangSec parsers to enforce boundaries against the hostile service indicators observed in the event. Patch these specific Citrix versions immediately to stop the exploit chain before it impacts production traffic.

Limits and watch

While setuid bit manipulation on /bin/sh confirms persistent root access, the specific data exfiltration paths and the full inventory of compromised internal systems have not been fully established. Watch for inbound network access to remote service ports that lines up with near-time service instability or abnormal restarts, since that pattern signals active exploitation of remote services for lateral movement.

Vulnerabilities

  • CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88778 — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

Techniques

  • T1021.001 Remote Desktop Protocol (Lateral Movement)
  • T1102 Web Service (Command And Control)
  • T1133 External Remote Services (Persistence)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1203 Exploitation for Client Execution (Execution)
  • T1204.002 Malicious File (Execution)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1212 Exploitation for Credential Access (Credential Access)
  • T1499.004 Application or System Exploitation (Impact)
  • T1505.003 Web Shell (Persistence)
  • and 3 more

Indicators

  • 4 indicators on file

Coverage


5. Zimbra CVE-2026-73570 Exploitation (Segment)

Event first seen in a show

Microsoft confirmed active exploitation of CVE-2026-73570, a critical unauthenticated command injection flaw in Zimbra Collaboration Suite versions prior to 10.1.20. Threat actors inject shell metacharacters via the SNMP notification path to gain root access, deploying JSP web shells and establishing reverse shells. The attack chain persists through systemd services and cron jobs while exfiltrating mailbox data and LDAP credentials using tools like AzCopy. Synacor patched the issue on July 20, but public disclosure did not occur until August 13. Microsoft observed scanning activity between July 28 and August 7, indicating a significant window of exposure. Shadowserver Foundation reports approximately ten thousand instances remain compromised. All reporting outlets agree on the mechanism and the patch version, 10.1.20. CISA has added this to its Known Exploited Vulnerabilities catalog, mandating federal patching by August 24. Synacor released version 10.1.20 on July 20, 2026, to remediate the defect. CERT Polska flagged the defect as actively exploited on August 17, 2026, corroborating the timeline established by Microsoft’s security research team. For detection engineering, look for unexpected JSP files in web directories and new systemd units or cron entries on Zimbra servers. Check for outbound connections to domains like dnslog[.]pp[.]ua or oast[.]fun, which appear in attacker infrastructure. If you run Zimbra with the zimbra-snmp package enabled, verify your patch level immediately. Focus on the SNMP path if you have not yet patched.

Attackers send specially crafted SMTP requests containing shell metacharacters to the SNMP notification path, bypassing input sanitization to execute arbitrary operating system commands as the Zimbra user. This flaw stems from improper neutralization of special elements in command construction, enabling attackers to bypass input validation through multiple parsing layers. The initial compromise allows attackers to deploy JSP web shells and modify PAM configuration files to escalate privileges from the Zimbra service account to root access. Zimbra Collaboration versions before 10.1.20 with the zimbra-snmp package allow remote code execution via crafted SMTP requests. This weakness enables full command execution with a CVSS 8.9 score, letting attackers disable the product or modify critical data without authentication. Compromised systems suffer theft of email backups and LDAP authentication credentials, alongside persistent access established through a systemd service named zimlog[.]service and cron jobs.

CVE-2026-73570 exposes Zimbra Collaboration Suite to unauthenticated command injection, allowing attackers to steal mailbox data and authentication secrets without prior credentials. This remote code execution weakness carries a CVSS score of 8.9, enabling full system compromise and immediate root access on internet-facing mail servers. Isolate affected systems immediately until patch 10.1.20 is applied. Disable the zimbra-snmp package or apply patch 10.1.20 immediately to prevent unauthorized code execution. Verify that all Zimbra Collaboration Suite instances are updated to version 10.1.20 immediately, as this is the specific release that remediates the command injection vulnerability in the SNMP notification path.

The vulnerability only affects systems where the optional zimbra-snmp package is installed and SNMP notifications are enabled, meaning environments without this specific configuration are not exposed to this particular injection vector. While the CVSS score is 8.9, the attack requires high complexity to exploit successfully, which may limit the immediate success rate of automated scanning attempts compared to simpler injection flaws. Monitor for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, as this behavior chain indicates active web shell deployment.

Vulnerabilities

  • CVE-2026-73570 — CVSS 8.9 (High) · CISA KEV · CWE-78 · Zimbra Collaboration. A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

Techniques

  • AML.T0006 Active Scanning (Reconnaissance)
  • AML.T0049 Exploit Public-Facing Application (Initial Access)
  • AML.T0050 Command and Scripting Interpreter (Execution)
  • AML.T0072 Reverse Shell (Command And Control)
  • T1053 Scheduled Task/Job (Execution)
  • T1053.005 Scheduled Task (Execution)
  • T1078.003 Local Accounts (Stealth)
  • T1087.001 Local Account (Discovery)
  • T1098.004 SSH Authorized Keys (Persistence)
  • T1114.002 Remote Email Collection (Collection)
  • and 9 more

Indicators

  • 21 indicators on file

Coverage


6. CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double (Segment)

Event first seen in a show

What changed

Threat actors exploited this flaw within four days of public disclosure, using malware such as SNOWLIGHT to exfiltrate data. This follows a Google Threat Intelligence Group report showing AI-assisted discovery has doubled monthly vulnerability disclosures to over ten thousand, with a significant rise in high-severity remote code execution flaws. Associated MITRE techniques include Exploitation of Remote Services and Remote Access Tools. While core facts are solid across five independent outlets, including CISA and The Record, specific malware families are reported with varying detail. Hacktron AI research agent autonomously identified a vulnerability that lets unauthenticated attackers execute OS commands directly on the host. BeyondTrust patched cloud deployments in early February 2026, yet approximately eleven thousand internet-facing instances remain exposed. CISA and The Record corroborated the vulnerability and its active exploitation, though specific malware families are reported with varying detail. Your SOC must immediately identify any exposed BeyondTrust instances in your perimeter.

How it works

Today, BeyondTrust Remote Support and Privileged Remote Access versions zero allow unauthenticated attackers to inject commands as site users via command injection. The flaw stems from improper neutralization of special elements when the software constructs commands using externally influenced input. An unauthenticated attacker sends specially crafted requests to the BeyondTrust application, which fails to neutralize special elements in the input, allowing the injection of operating system commands. The injected commands execute in the context of the site user, granting the attacker remote code execution capabilities without requiring prior authentication or user interaction. A critical pre-authentication flaw allows remote attackers to execute site user commands, bypassing standard access controls. This vulnerability carries a CVSS score of 9.8, granting full integrity and unauthorized code execution.

What to do

CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities catalog, making the unauthenticated remote code execution flaw in BeyondTrust Remote Support and Privileged Remote Access an active federal compliance requirement under Binding Operational Directive 22-01. Patch BeyondTrust RS and PRA immediately to stop remote code execution before the next attack wave arrives. Identify and patch all self-hosted BeyondTrust Remote Support and Privileged Remote Access instances to versions 25.3.2 and 25.1.1 or later, as cloud deployments were already remediated on February 2, 2026. Prioritize network segmentation for any remaining unpatched instances to prevent unauthenticated attackers from reaching the remote service ports that enable command injection. Validate all external inputs against known good lists and avoid dynamic command construction until patches arrive. Verify static analysis scans for command construction and block control characters in incoming remote session data immediately. Isolate affected systems and apply the architecture and design mitigation to prevent unauthorized code execution. Assume all remote input is malicious and switch to static command construction to stop the command injection attack pattern.

Limits and watch

Static analysis tools can detect this weakness, but we cannot confirm a patch date for the affected products yet. The specific malware families involved in the active exploitation of CVE-2026-1731 are reported with varying detail across sources, making it difficult to confirm a single consistent payload signature for detection. While both CVE-2024-12356 and CVE-2026-1731 share a CVSS score of 9.8 and pre-authentication access requirements, the exact version ranges affected by the older CVE-2024-12356 are not clearly distinguished from the newer flaw in the provided evidence. Watch for repeated detection of control characters by input filters, as this specific indicator signals an attempt to exploit multiple input interpretation layers in the remote service.

Vulnerabilities

  • CVE-2024-12356 — CVSS 9.8 (Critical) · CISA KEV · CWE-77 · BeyondTrust Remote Support; BeyondTrust Privileged Remote Access. A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
  • CVE-2026-1731 — CVSS 9.8 (Critical) · CISA KEV · CWE-78 · BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA). BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.

Techniques

  • AML.T0001 Search Open AI Vulnerability Analysis (Reconnaissance)
  • AML.T0010.005 AI Agent Tool (Initial Access)
  • AML.T0016.002 Generative AI (Resource Development)
  • AML.T0103 Deploy AI Agent (Execution)
  • T1203 Exploitation for Client Execution (Execution)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1219 Remote Access Tools (Command And Control)
  • T1588.007 Artificial Intelligence (Resource Development)

Coverage


7. Cisco patches actively exploited zero-day in Catalyst SD-WAN Controller (Segment)

Event first seen in a show

What changed

Cisco released emergency updates for CVE-2026-20182, a critical zero-day authentication bypass in the Catalyst SD-WAN Controller that has been actively exploited since 2023. Unauthenticated attackers bypass DTLS authentication in the vdaemon service by impersonating a vHub device, allowing them to inject SSH keys into the vmanage-admin account and execute arbitrary commands via NETCONF for full administrative control. Rapid7 Labs discovered the flaw while researching CVE-2026-20127, and CISA added it to the Known Exploited Vulnerabilities Catalog with a May 17, 2026 deadline. All five reporting outlets agree on the technical mechanism and the lack of available workarounds. If you run Catalyst SD-WAN, verify your patch status immediately. Before upgrading, collect admin-tech logs for TAC analysis to check for prior intrusion. Watch for unexpected SSH key additions to the vmanage-admin account or anomalous NETCONF sessions.

How it works

Cisco’s May 2026 advisory confirms that exploitation is limited to specific control components and requires the collection of admin-tech logs for TAC analysis to verify prior intrusion. The mechanism involves Cisco Catalyst SD-WAN Manager 20.1.12 allowing unauthenticated attackers to bypass peering authentication using crafted requests. The peering authentication mechanism fails to verify identity, letting attackers log in as high-privileged non-root users. This improper authentication flaw enables attackers to assume the identity of an internal high-privileged user. By exploiting this gap, attackers can access NETCONF. Today, an unauthenticated remote attacker bypassed peering auth in Cisco Catalyst SD-WAN Controller versions like 20.6.4 to gain admin access. That breach grants NETCONF control, enabling configuration manipulation across the entire SD-WAN fabric without requiring network exposure. Exploitation affects versions from 17.2.1 through 20.16.1 and higher, while static analysis tools struggle to detect this improper authentication flaw. The flaw impacts all deployment types, including on-premises, cloud, and government environments, and is distinct from CVE-2026-20127 because it resides in a different part of the networking stack despite sharing the same impact. The vulnerability carries a CVSSv3.1 score of 10.0 and allows for persistent SSH key injection, enabling adversaries to maintain access and manipulate network configurations within the SD-WAN fabric. Cisco Catalyst SD-WAN Controller deployments face active exploitation of a critical authentication bypass that grants unauthenticated attackers administrative control over the network fabric. Once logged in, attackers can manipulate the SD-WAN fabric through NETCONF, potentially compromising the entire network fabric.

What to do

Verify your specific controller version against the full list to confirm protection against this improper authentication issue. Check your SD-WAN Manager inventory against the affected list and apply the latest patch immediately to restore proper authentication controls. Verify NETCONF access on affected versions and apply architecture-based authentication frameworks to prevent unauthorized configuration manipulation. Verify control connection handshakes immediately to prevent NETCONF manipulation of the SD-WAN fabric configuration. Verify authentication framework usage for affected versions and watch for identity spoofing indicators in the fabric. Restrict access to management interfaces and apply the released security updates to mitigate the risk, as no workarounds are available for this authentication bypass.

Limits and watch

The exact scope of prior exploitation remains uncertain until the Cisco TAC compromise scan of the collected admin-tech logs is completed. Automated static analysis tools have difficulty detecting custom authentication schemes, which limits the ability to identify this specific peering authentication flaw through standard configuration file analysis. Watch vdaemon logs for DTLS bypass attempts. Signals vHub impersonation. Adversary action.

Vulnerabilities

  • CVE-2026-20127 — CVSS 10 (Critical) · CISA KEV · CWE-287 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN…
  • CVE-2026-20182 — CVSS 10 (Critical) · CISA KEV · CWE-287 · Cisco Cisco Catalyst SD-WAN Controller; Cisco Cisco Catalyst SD-WAN Manager. May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026.

Techniques

  • T1021 Remote Services (Lateral Movement)
  • T1133 External Remote Services (Persistence)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1212 Exploitation for Credential Access (Credential Access)

Indicators

  • 8 indicators on file

Coverage


8. CISA Mandates Patch for Critical Cisco SD-WAN Auth Bypass (Segment)

Event first seen in a show

CISA added CVE-2026-76504 to its Known Exploited Vulnerabilities catalog on Wednesday, October 1, 2026, mandating that federal agencies patch the flaw by October 3. Cisco confirmed that active exploitation of this zero-day began in September 2026, targeting the Catalyst SD-WAN Manager API. The vulnerability carries a CVSS score of 9.8. CISA has added a critical Cisco vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies until October third to patch. The flaw allows unauthenticated attackers to bypass authentication on Catalyst SD-WAN Manager by sending crafted requests to the j_security_check endpoint. Fixed versions include 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, and 26.2.1. For detection engineering, look for anomalous HTTP requests targeting the j_security_check endpoint with malformed URI encoding. If you run on-premises SD-WAN Manager, you are exposed until you upgrade. Cisco has released software updates to address the issue, with fixed versions including 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, and 26.2.1.

Cisco Catalyst SD-WAN Manager versions through 18.4.3 allow an unauthenticated attacker to bypass admin-only API rules by double-encoding URL slashes. The flaw stems from improper handling of URI encoding in the API session-based authentication management, specifically within the j_security_check endpoint. Cisco Catalyst SD-WAN Manager has a critical flaw scoring nine point eight on the CVSS scale. This double-encoding issue, rooted in CWE-177, lets attackers gain full admin privileges without credentials. The system behaves as if an authorized administrator is present, allowing immediate lateral movement across the fabric. Attackers can alter system state without authentication, creating a severe integrity breach. The vulnerability affects all configurations and releases prior to the fixed versions, including the 17.2, 18.2, 18.3, and 18.4 series. Successful exploitation grants administrative control over the network without any network access precondition.

Cisco Catalyst SD-WAN Manager instances running versions 17.2.4 through 18.4.3 are exposed to unauthenticated remote access that grants full administrative privileges. Because the flaw bypasses authentication entirely, any internet-facing or internal SD-WAN Manager instance in the affected range is a direct entry point for lateral movement into the network. Defenders gain clarity by recognizing that traffic filtering alone fails against double-encoded payloads like %252E, necessitating immediate input validation updates for the affected SD-WAN Manager instances. Upgrade all affected Cisco Catalyst SD-WAN Manager instances to version 20[.]9[.]10[.]1, 20[.]15[.]6[.]1, or 26.2.1 immediately, as no workarounds exist for this authentication bypass. Validate every URL input against a strict allowlist and reject any request containing invalid or denylisted characters after the first decode. Check all URL inputs against known-good specifications immediately, as standard filters often miss doubly encoded payloads like %252E. Validate all URL inputs against a strict allowlist for the affected Cisco Catalyst SD-WAN Manager releases to block this bypass.

Traffic filtering can flag suspicious double-encoded requests, but the application fails to detect the encoding, so the exploit succeeds regardless of IDS signatures, leaving the system in an unexpected integrity state until patched. The advisory does not detail the specific URI encoding patterns used in active exploitation, making it difficult to distinguish malicious double-encoding from legitimate client behavior without additional context. It remains unclear whether the vulnerability can be leveraged to execute arbitrary code beyond the API authentication bypass, as current evidence only confirms administrative access to the API. Monitor for IDS alerts flagging requests where the first decoding process leaves invalid or denylisted characters, indicating potential URL encoding bypass attempts. Watch for post-compromise lateral movement signals, such as suspicious child process creation or shell spawning from the SD-WAN Manager service context after successful exploitation.

Vulnerabilities

  • CVE-2026-76504 — CVSS 9.8 (Critical) · CWE-177 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.

Techniques

  • AML.T0106 Exploitation for Credential Access (Credential Access)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1203 Exploitation for Client Execution (Execution)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1212 Exploitation for Credential Access (Credential Access)

Indicators

  • 4 indicators on file

Coverage


9. New Spectre v2 Variant Leaks Linux Root Hashes via JIT Engines (Segment)

No material change since last show

What changed

Researchers from VUsec and Scuola Superiore Sant’Anna disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor data to recover Linux root password hashes. The attack targets the interaction between self-modifying code and branch predictors in environments like Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. On modern Intel, AMD, and Arm processors, local attackers can use this to recover root password hashes. Proof-of-concept exploits demonstrated that the vulnerability bypasses existing mitigations like FineIBT, recovering credentials in three to five minutes on fully patched systems. The vulnerability is assigned CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel. Mitigations have already been merged into the Linux kernel and adopted by Oracle and Mozilla. The lead sheet tracks the specific JIT engine configurations and the kernel patch versions that close this gap. Proof-of-concept exploits have demonstrated that the attack can leak and recover root password hashes within minutes on fully patched Intel systems with default protections enabled. Leakage rates were measured at approximately 5.4 KB per second on Lion Cove processors and 5.7 KB per second on Raptor Cove chips. The attack bypasses existing mitigations such as FineIBT, confirming that speculative execution risks persist in JIT engines despite previous hardening efforts.

How it works

Today’s Linux kernel update resolves CVE-2026-64507 by forcing an Instruction Buffer Privilege Bypass flush specifically when the BPF JIT compiler reuses memory, a hardening that only activates if CONFIG_BPF_JIT is enabled. It also resolves CVE-2026-64508 by adding a branch predictor flush when reusing JIT memory, preventing old indirect jump predictions from contaminating fresh code. By hijacking speculative control flow to newly generated code at obsolete offsets, local attackers can leak arbitrary memory on modern Intel CPUs. The vulnerability affects Linux kernel versions 5.18 through 7.2, specifically targeting the BPF JIT allocator where small programs are packed into larger executable allocations. This fix protects systems running kernel versions 5.18 through 7.2 from Spectre-v2 JIT spraying attacks that previously exploited the BPF dispatcher’s lack of isolation during memory reuse. This fix covers Linux 5.18 through 7.2 versions but leaves allocations larger than a pack unprotected, a safe boundary since unprivileged cBPF programs stay well below that size. Successful exploitation allows adversaries to recover root password hashes, which can then be cracked offline to gain full system access.

What to do

This exposure confirms that local attackers can still extract high-value credentials from environments where JIT engines are not properly hardened against stale branch predictor data. Apply the Linux kernel patches for CVE-2026-64507 and CVE-2026-64508 to enable the IBPB flush on BPF JIT memory reuse, specifically targeting versions 5.18, 6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4, and 7.2. Operators deploying kernels 6.1.183 or later must verify their BPF JIT configuration today to ensure the IBPB flush logic is active before any JIT spraying attempt could succeed. Operators on affected kernels must verify their specific version matches the hardened baseline to ensure the JIT spray mitigation is active. Verify that the bpf_arch_pred_flush_enabled static key is active on affected hosts to ensure the branch predictor flush executes before reusing JIT memory allocations.

Limits and watch

The IBPB flush mitigation for CVE-2026-64507 is skipped if the BPF dispatcher is already using a retpoline sequence, leaving a potential gap in protection for those specific configurations. The flush for CVE-2026-64508 does not cover allocations larger than a pack, relying on the assumption that cBPF programs remain bounded well below that size to maintain safety. Watch for John the Ripper or Hashcat running after shadow files or dumped hashes are accessed, since that marks post-credential dump activity.

Vulnerabilities

  • CVE-2026-64507 — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use.
  • CVE-2026-64508 — CVSS 0 (Low) · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space…

Techniques

  • T1110.002 Password Cracking (Credential Access)
  • T1205.002 Socket Filters (Stealth)

Coverage


10. OWASP ModSecurity WAF Bypass Flaws Disclosed (Hot)

Event first seen in a show

Yesterday, OWASP ModSecurity dropped ten security advisories exposing a critical gap in your perimeter. Attackers exploit differences in how Go, Python, Node[.]js, and Java backends handle RFC 2231 filenames, Base64 decoding, and comment removal to bypass firewall protections. Maintainer airween published these updates on GitHub Security Advisories between April and September 2026, identifying high-severity issues from RFC 2231 parameter bypasses to TLS hostname verification errors. The owasp-modsecurity/ModSecurity project confirmed these vulnerabilities through specific GitHub Security Advisory identifiers, including GHSA-5pww-8rfg-9crf, GHSA-4j47-8qcr-jf59, and GHSA-qrch-pjfr-9g47. While some of these issues lack assigned CVEs, the project has verified their security impact, confirming that they enable malicious file uploads and evasion of signature-based filtering. Upgrade immediately to ModSecurity version 2.9.15 or 3.0.17 and verify your current version against the eight listed GHSA identifiers.

Attackers exploit parsing differences and transformation errors in how ModSecurity handles HTTP requests, specifically leveraging RFC 2231 filename mismatches and incorrect Base64 decoding to evade detection. These flaws also involve improper comment removal in request processing and an uninitialized pointer dereference, which allows attackers to trigger denial-of-service conditions or bypass WAF rules entirely. ModSecurity versions 2.9.15 and 3.0.17 face multipart parsing errors and pattern matching obfuscation. Adversaries can execute malicious requests that bypass standard WAF protections, rendering the firewall blind to specific evasion techniques. If you are running versions prior to 2.9.15 or 3.0.17, your WAF is effectively blind to these specific RFC 2231 and Base64 evasion techniques.

If you cannot patch immediately, tighten upstream input validation to compensate for the WAF’s blind spots regarding malicious file execution.

Watch for a spawn chain where a user opens a file in Downloads or Temp and then executes a new child process like powershell[.]exe or cmd[.]exe.

Techniques

  • T1204.002 Malicious File (Execution)
  • T1505.003 Web Shell (Persistence)

Indicators

  • 11 indicators on file

Coverage