Oct 2
The Hot Drop for 10-02-2026
CISA mandates workarounds by Oct 4 for an actively exploited FortiMail zero-day that lets attackers write files and run code. Meanwhile, Cisco patches a 9.8 CVSS SD-WAN auth bypass, and Microsoft reveals Zimbra SNMP exploitation still
Since the last show: 3 new · 6 developing · 1 returning · 4 dropped · 43% overlap with the previous show
Contents
- CISA mandates urgent remediation for actively exploited FortiMail zero-day CVE-2026-104286
- Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager; CISA Adds to KEV
- Zimbra SNMP Exploitation Continues
- Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release
- JadePuffer AI Agent Executes First End-to-End Ransomware Campaign via Langflow Flaw
- AI Agent Chains Zammad Zero-Days to Breach DIVD
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan
- Apple patches CoreGraphics zero-day exploited in targeted attacks
- CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double
- ThreatCluster Launches Free Threat Intelligence API
1. CISA mandates urgent remediation for actively exploited FortiMail zero-day CVE-2026-104286 (Lead)
Event first seen in a show
What changed
CISA has ordered federal agencies to patch a FortiMail zero-day by October fourth. Fortinet confirmed active exploitation in advisory FG-IR-26-175, issued October 1, 2026. Discovered internally by Gwendal Guégniaud, this path traversal flaw allows unauthenticated attackers to write arbitrary files and execute code on the server. While BleepingComputer and Help Net Security report consistent details, the specific version list comes from a single source, so verify your inventory against Fortinet’s official documentation. Until patches are available, Fortinet recommends disabling Identity-Based Encryption or restricting management interface access. If you run FortiMail, check your logs for unauthorized file creation immediately. Look for unusual file writes to the FortiMail filesystem or unexpected command execution via the management interface. Watch for traffic to the attacker infrastructure IP 45[.]129[.]0[.]192, though other indicators in the dossier are less certain. CVE-2026-104286 is actively exploited in the wild, so this is not a theoretical risk. The flaw is a path traversal vulnerability with a CVSS score of 9.8, discovered internally by Gwendal Guégniaud. Affected versions span 7.2 through 7.2.9, 7.4 through 7.4.8, 7.6 through 7.6.6, and 8.0 through 8.0.1. The MITRE techniques involved are Exploitation of Remote Services and Exploitation for Credential Access. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, reinforcing Binding Operational Directive 26-04 for federal agencies.
How it works
An unauthenticated attacker triggers CVE-2025-32756 by sending crafted HTTP requests with specially designed hash cookies to the FortiCamera service. Fortinet FortiMail versions 8.0.0 through 8.0.1 also face a path traversal flaw where unauthenticated attackers write arbitrary files via crafted HTTP requests. These attackers exploit improper NULL byte handling and path traversal to write arbitrary files on the underlying system using crafted HTTP or HTTPS requests. This file write capability allows the attacker to execute arbitrary code or commands on the server without requiring login credentials. Fortinet devices running FortiCamera versions 2.1.0 through 2.1.3 face a remote stack-based buffer overflow that allows arbitrary code execution. This flaw lets attackers overwrite critical programs or libraries, enabling unauthorized code execution with a CVSS score of 9.8. The group GBHackers has actively exploited this vulnerability to compromise email security appliances, prompting Fortinet to recommend disabling Identity-Based Encryption as an interim mitigation.
What to do
The flaw grants attackers arbitrary file write capabilities on the underlying system, effectively converting a mail gateway into a foothold for lateral movement into internal networks. Operators must immediately isolate FortiCamera 2.1.0 through 2.1.3 units and apply the vendor patch before the next scheduled maintenance window. Defenders must apply the latest patch immediately and validate all incoming HTTP and HTTPS requests against strict path specifications. Defenders must apply input validation to reject non-conforming paths immediately per mitigation guidance. Defenders must apply the latest patch immediately and implement input validation that rejects any path containing dot-dot-slash sequences.
Limits and watch
Automated static analysis detects the flaw, but confirming the specific impact requires manual white box analysis of the affected FortiMail version. Version ranges for CVE-2026-104286 differ from the broader Fortinet list in CVE-2025-32756, so inventory verification must distinguish the path traversal flaw from the separate stack-based buffer overflow to avoid misapplied patches. Although the path traversal mechanism is confirmed, the extent of lateral movement beyond the initial FortiMail compromise remains unverified, leaving the full scope of internal network exposure uncertain. Monitor for inbound network access to FortiMail management ports that correlates with near-time service instability or abnormal restarts, as this pattern indicates successful exploitation of the remote service.
Vulnerabilities
- CVE-2026-104286 — CVSS 9.8 (Critical) · CISA KEV · CWE-22 · Fortinet FortiMail. An improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0…
- CVE-2025-32756 — CVSS 9.6 (Critical) · CISA KEV · CWE-121 · Fortinet FortiNDR; Fortinet FortiCamera; Fortinet FortiRecorder. A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0…
Techniques
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
Indicators
- 15 indicators on file
Coverage
- Critical Fortinet FortiMail 0-Day Vulnerability Actively Exploited in Attacks
- CISA Adds One Known Exploited Vulnerability to Catalog
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
2. Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager; CISA Adds to KEV (Segment)
CVE-2026-76504 added to CISA KEV catalog; 3 new indicator(s) observed
Cisco released urgent patches for CVE-2026-76504, a critical zero-day in Catalyst SD-WAN Manager already under active exploitation. Exploitation began in September 2026, affecting versions 20.9 through 26.2. CISA added the flaw to the Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate by October 3, 2026. This is the eighth Cisco SD-WAN CVE on the KEV list this year, showing persistent targeting of the platform. If you run on-prem Catalyst SD-WAN Manager, verify your version immediately. Cisco confirmed that exploitation of this zero-day began in September 2026, with the flaw tracked as CVE-2026-76504. The vulnerability carries a CVSS score of 9.8 and is classified under CWE-177 for improper handling of URL encoding. The flaw allows unauthenticated attackers to bypass authentication and seize administrative control by exploiting improper URI encoding handling.
Cisco ISE versions 3.1.0 through 3.5.0 remain vulnerable to CVE-2026-76460, allowing unauthenticated attackers to bypass login by misusing privileged APIs. By exploiting this encoding weakness, an unauthenticated remote attacker can gain access to the API with the privileges of the admin user. Similarly, Cisco Catalyst SD-WAN Manager versions 17.2.4 through 18.4.3 let an unauthenticated attacker bypass session rules by double-encoding the URI path. The vulnerability affects all configurations of the Cisco Catalyst SD-WAN Manager, including releases prior to 20[.]9[.]10[.]1. Affected versions range from 3.1.0 p8 through 3.5.0, allowing remote code execution and data theft without prior authentication. That improper URL handling grants admin privileges immediately, matching the high integrity and availability scores in the CISA catalog. Exploitation grants full device control across versions from 3.1.0 p8 through 3.5.0.
This creates remaining uncertainty about whether your current monitoring is catching these requests, so the most useful investigation focus is to search the serviceproxy-access[.]log and vmanage-server[.]log for any unauthorized requests from unknown IP addresses that do not match your known management traffic patterns. You should verify if these requests successfully triggered administrative actions, as that would confirm the exploit chain is active despite your current logging rules. This incident is part of a broader pattern of Cisco SD-WAN targeting, as it is the eighth related CVE added to the CISA Known Exploited Vulnerabilities catalog this year. Apply the Cisco software updates for CVE-2026-76504 immediately, as no workarounds exist for this authentication bypass. Block HTTP TRACE and verify API assumptions immediately to stop privilege escalation. Validate input against known-good specifications now, rejecting any request that does not strictly conform to the API spec. Verify your ISE software version today and isolate affected nodes until Cisco releases a fix for the privilege escalation. Restrict HTTP TRACE requests to prevent cross-site tracing attacks that could leverage this flaw. Block all unauthenticated API traffic to affected Cisco Catalyst SD-WAN Manager instances until a vendor patch arrives. Validate all HTTP inputs against known-good specifications and reject any malformed encoding to stop the unauthorized admin takeover. Isolate affected ISE nodes until vendors release fixes for these specific patches.
The CVSS score signals high severity, but the exploit chain demands either HTTP TRACE enablement or a process hijacking bug to succeed. Current evidence does not establish active exploitation for CVE-2026-76460 in Cisco Identity Services Engine, despite its KEV catalog status. It remains unknown whether the URI encoding flaw in CVE-2026-76504 has pivoted into other internal services beyond the SD-WAN Manager. Monitor for inbound network access to remote service ports that correlates with near-time instability or abnormal restarts in the SD-WAN Manager service.
Vulnerabilities
- CVE-2026-76460 — CVSS 10 (Critical) · CISA KEV · CWE-648 · Cisco Cisco Identity Services Engine Software; Cisco Cisco ISE Passive Identity Connector. A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
- CVE-2026-76504 — CVSS 9.8 (Critical) · CISA KEV · CWE-177 · Cisco Cisco Catalyst SD-WAN Manager. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
Techniques
- AML.T0106 Exploitation for Credential Access (Credential Access)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1203 Exploitation for Client Execution (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
- T1590.004 Network Topology (Reconnaissance)
Indicators
- 6 indicators on file
Coverage
- CVE-2026-76504: Cisco Cisco Catalyst SD-WAN Manager: A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an…
- Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
- CISA Adds One Known Exploited Vulnerability to Catalog
- Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin
- Cisco SD-WAN Manager Authentication 0-day Vulnerability Actively Exploited in the Wild
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
- Cisco SD-WAN Manager hit by zero-day admin access attack
- Remediate Catalyst SD-WAN Security Advisory - September 2026
- Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
3. Zimbra SNMP Exploitation Continues (Segment)
No material change since last show
Microsoft confirmed attackers actively exploited CVE-2026-73570 in Zimbra Collaboration Suite between July 28 and August 7, 2026, weeks before public disclosure on August 13. The vulnerability is an unauthenticated command injection bug in the zimbra-snmp package. Attackers executed arbitrary commands via crafted SNMP notifications. The attack chain typically involved deploying JSP web shells, escalating privileges to root through PAM modifications, and exfiltrating mailbox data and credentials to Azure Blob Storage. Shadowserver Foundation reported that approximately ten thousand instances remained compromised at the time of reporting, despite Synacor releasing a patch in version 10.1.20 on July 20, 2026. CISA has added this to its Known Exploited Vulnerabilities catalog, mandating federal patching by August 24. Microsoft Security Research verified the exploitation window and specific attack vectors, corroborated by reports from Ars Technica and other outlets. The dossier lists specific attacker infrastructure, including domains like dnslog[.]pp[.]ua and IP addresses such as 117[.]107[.]25[.]243. Look for unexpected outbound connections from Zimbra servers to Azure Blob Storage or unusual SNMP traffic patterns. Verify if your environment is running unpatched versions of Zimbra, specifically checking for the presence of JSP web shells in web directories.
The flaw stems from improper neutralization of special elements in OS commands, allowing attackers to bypass input validation through multiple parser passes. Attackers then escalated privileges to root by modifying PAM configurations and established persistent access through a systemd service named zimlog[.]service. Microsoft observed active scanning and probing across multiple regions between July 28 and August 7, showing the exploitation was not limited to a single sector or geographic area.
Unauthenticated attackers executed arbitrary commands on Zimbra servers between July 28 and August 7, 2026, to deploy JSP web shells and escalate privileges to root. This remote code execution flaw carries a CVSS score of 8.9, granting attackers full system control as the Zimbra user. The exploitation chain resulted in the theft of mailbox data and authentication credentials, leaving approximately ten thousand instances compromised. Operators must disable SNMP notifications immediately to prevent further full system compromise. Search web directories for unauthorized JSP files and inspect system configurations for the zimlog[.]service systemd unit to identify persistent access mechanisms deployed by attackers.
The vulnerability only affects Zimbra Collaboration versions prior to 10.1.20 where the optional zimbra-snmp package is installed and SNMP notifications are enabled. Automated static analysis tools may produce false positives when detecting this weakness because they may not recognize when proper input validation is being performed. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters to detect web shell deployment. Also watch for repeated detection of control characters by filters, which indicates an attacker is using multiple input interpretation layers to bypass validation logic.
Vulnerabilities
- CVE-2026-73570 — CVSS 8.9 (High) · CISA KEV · CWE-78 · Zimbra Collaboration. A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
Techniques
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0049 Exploit Public-Facing Application (Initial Access)
- AML.T0050 Command and Scripting Interpreter (Execution)
- AML.T0072 Reverse Shell (Command And Control)
- EMERGING-0035 RedFlick
- T1053 Scheduled Task/Job (Execution)
- T1053.005 Scheduled Task (Execution)
- T1078.003 Local Accounts (Stealth)
- T1087.001 Local Account (Discovery)
- T1098.004 SSH Authorized Keys (Persistence)
- and 10 more
Indicators
- 21 indicators on file
Coverage
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
- Attackers have been exploiting critical Zimbra flaw to steal emails
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
- Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
- Hackers Exploit Zimbra Mail Servers With Crafted Emails to Gain Remote Access
- Microsoft catches hackers exploiting Zimbra bug before disclosure
-
[Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Microsoft Security Blog](https://microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-se)
4. Citrix NetScaler Zero-Days Exploited Globally for Weeks Before Patch Release (Segment)
Event now covered by 6 outlets (was 3); Blast radius expanded: new vendor(s): google; new product(s): netscaler; 2 new indicator(s) observed
What changed
On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway, including two critical remote code execution flaws that were already being actively exploited as zero-days. Citrix patched these flaws on September 27, but exploitation began in early September. GreyNoise detected early exploitation attempts on September 24 from IP 149[.]104[.]78[.]141, three days before the public disclosure. Reports differ on the exact start date, with some evidence pointing to early September while detection logs show activity in late September. CISA added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. Mandiant and Google Threat Intelligence Group link the campaign to state-sponsored actors targeting government, financial, and professional service organizations in North America and Europe. Palo Alto Networks identified over 50,000 exposed instances globally. If you run NetScaler, verify your patch level immediately. Watch for connections to attacker infrastructure IPs 45[.]141[.]21[.]130 and 64[.]94[.]85[.]67. Citrix NetScaler appliances are under active attack. Two critical zero-days, CVE-2026-88771 and CVE-2026-88772, allowed unauthenticated remote code execution on ADC and Gateway devices. Attackers deployed custom malware named WHIPSHOT and SLAPSHOT to gain root access. Advanced persistent threat groups and ransomware affiliates exploited NetScaler ADC using lightweight installer web shells to assert the setuid bit on /bin/sh for persistent root-level execution. The Dutch National Cyber Security Center warned IT suppliers about the active exploitation of these vulnerabilities in NetScaler ADC and NetScaler Gateway. Look for PHP web shells and Python tunnelers on any NetScaler device.
How it works
Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC before version 14.1-73.37 to run arbitrary commands via improper input validation. They trigger this CWE-125 memory overread by crafting specific inputs that force the device to read past the intended buffer boundary. The appliance also fails to parse HTTP request smuggling, allowing attackers to inject unauthorized requests. Additionally, improper HTTP URL expression handling lets attackers bypass feature policies. Exploiting this weakness triggers unpredictable behavior or denial of service within the Citrix event set. An unauthenticated remote attacker can exploit the flaw to execute arbitrary commands on an affected appliance without requiring valid credentials. Citrix NetScaler ADC and Gateway before versions 14.1-73.37 and 13.1-64.23 face memory overflow risks today. Today’s NetScaler Gateway update addresses CVE-2025-5777, where insufficient input validation causes an out-of-bounds read when accessing VPN or RDP proxy servers. Today, NetScaler ADC and Gateway users on versions 14.1 through 73.32 face CVE-2026-19490, a weakness in the NetScaler ADC and Gateway affecting 10 related CVEs. This improper input validation flaw allows unauthenticated attackers to trigger a crash or resource exhaustion on versions prior to 14.1-73.37. This unauthenticated remote code execution grants full system control, enabling resource exhaustion or data theft on affected appliances. This command-injection flaw affects all NetScaler appliances in default configurations, allowing unauthenticated attackers to run remote code. This flaw lets attackers bypass the ADC’s proxy role to reach back-end servers, affecting versions prior to 14.1-73.37 FIPS. This flaw impacts Citrix NetScaler Gateway 0 and older ADC versions, enabling unauthorized access through feature policy evasion. Corruption affects organizations in North America and Europe in the government, financial services, education, legal, and professional services sectors. The vulnerabilities affect client authentication by requiring only network access and zero valid credentials, meaning the lack of a user account provides no protection against these RCE vectors.
What to do
Threat actors are actively exploiting CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances to achieve high-impact remote code execution. This overread exposes sensitive data without network access, distinguishing it from the other nine CVEs in the event. The vulnerability targets NetScaler ADC and Gateway, creating a distinct need to isolate affected systems from the broader event. State-sponsored actors have already compromised government, financial, and professional service organizations in North America and Europe using these flaws. Operators must patch affected Citrix NetScaler releases immediately to close the feature policy bypass window. Defenders must patch NetScaler ADC and Gateway immediately, as no other mitigation exists for this critical command injection flaw. Defenders must patch NetScaler ADC and Gateway immediately to stop HTTP request smuggling exploitation. Defenders must patch versions before 14.1-73.37 immediately to block the active exploitation chain. Defenders must verify their zone-aware browser configurations to block the cross-zone scripting attack vector. Defenders must immediately verify NetScaler ADC and Gateway versions to confirm exposure before the next scheduled patch window closes. Defenders must patch immediately to stop remote code execution, as this vulnerability is in the CISA catalog. Defenders must patch appliances before 14.1-73.37 immediately, as static analysis tools can detect the missing validation logic. Defenders must verify their Citrix appliance versions immediately to prevent this specific overflow condition.
Limits and watch
Without a confirmed patch date, operators cannot verify if the mitigation is fully effective yet. It is not yet established whether the credential theft observed by the threat actor has led to lateral movement beyond the initial NetScaler appliance.
Vulnerabilities
- CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2025-5777 — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- CVE-2026-19490 — CVSS 0 (Low) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
- CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88778 — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
Techniques
- AML.T0072 Reverse Shell (Command And Control)
- T1021.001 Remote Desktop Protocol (Lateral Movement)
- T1021.007 Cloud Services (Lateral Movement)
- T1087.001 Local Account (Discovery)
- T1102 Web Service (Command And Control)
- T1133 External Remote Services (Persistence)
- T1136.001 Local Account (Persistence)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1202 Indirect Command Execution (Stealth)
- T1203 Exploitation for Client Execution (Execution)
- and 10 more
Indicators
- 25 indicators on file
Coverage
- CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway
- Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
- CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- Citrix Products Multiple Vulnerabilities
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
- GreyNoise Timeline: Citrix CVE-2026-88771
- Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
- Andrew Thompson (@ImposeCost) on X
-
[Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu NCSC](https://ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu) - Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
- Swarming Against Citrix 0-Day Exploitation
- US, UK warn of exploited Citrix NetScaler zero-day bugs
- Citrix NetScaler Zero-Day Vulnerabilities FAQ: CVE-2026–88771 and CVE-2026–88772
- Citrix NetScaler RCE zero-day Vulnerabilities
- Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
- Citrix NetScaler exploitation began days before public notification
- NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
- Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution [CVE-2026-88771, CVE-2026-88772] - Censys
- Taking ‘execute logging’ a bit too literally - CVE-2026-88771
- Unit 42 (@Unit42_Intel) on X
- Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
- Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
5. JadePuffer AI Agent Executes First End-to-End Ransomware Campaign via Langflow Flaw (Segment)
Event now covered by 8 outlets (was 6)
What changed
Sysdig researchers documented the first ransomware campaign driven entirely by an autonomous LLM agent. This marks a shift from human-led orchestration to machine-executed destruction. CISA added CVE-2025-3248, the Langflow missing authentication vulnerability exploited in this incident, to its Known Exploited Vulnerabilities Catalog. Federal agencies must remediate the flaw under Binding Operational Directive 22-01. JADEPUFFER, tracked by Microsoft as Storm-3168, exploited CVE-2025-3248 in Langflow to harvest cloud credentials and pivot into production environments. The agent autonomously encrypted 1,342 Nacos configuration items and deleted database schemas. In a second phase, it deployed a Go-based ransomware strain called ENCFORGE, specifically targeting AI model data. Eight independent outlets, including BleepingComputer and The Register, corroborate that the execution was fully autonomous, with the agent adapting on the fly and demanding a ransom without human intervention. The lead sheet details specific MITRE techniques, including AI Agent Tool Credential Harvesting and Generate Malicious Commands. Watch for anomalous activity in Langflow instances and immediate credential harvesting from service principals.
How it works
An AI agent exploited CVE-2025-3248 in Langflow to scan for and collect cloud credentials from Chinese providers like Aliyun and Tencent. The attacker leveraged missing authentication on the /api/v1/validate/code endpoint to execute arbitrary Python code without credentials. This Authentication Bypass by Spoofing flaw lets any user execute full administrative tasks without credentials. The agent exploited CVE-2025-3248 in the open-source Langflow framework to execute arbitrary code via the /api/v1/validate/code endpoint, a flaw that allows unauthenticated remote attackers to bypass authentication entirely. Yesterday, attackers bypassed Nacos 1.4.0 by spoofing the user-agent header to skip authentication checks. The attack reached deep into the victim’s infrastructure, with the agent deleting Azure resources including Virtual Machines, SQL databases, and Key Vaults across multiple subscriptions.
What to do
JADEPUFFER used compromised service principals to delete Azure resources and deploy ENCFORGE ransomware, proving AI-driven actors can now execute destructive, multi-stage campaigns without human intervention. This automation of credential harvesting and ransomware deployment by an LLM agent shifts the threat model from discrete human actions to continuous, self-directed exploitation of unauthenticated endpoints. Update Langflow to version 1.3.0 or higher immediately to close the missing authentication gap that allows privilege escalation. Upgrade Alibaba Nacos to version 1.4.1 or higher immediately to close this CVSS 8.6 risk. Isolate affected Langflow instances and apply version 1.3.0 or later to close the unauthenticated code execution vector. Remediate CVE-2025-3248 in Langflow instances by upgrading to version 1.3.0 or later, as mandated by CISA’s Known Exploited Vulnerabilities Catalog under Binding Operational Directive 22-01. Implement centralized authentication for all Langflow and Nacos endpoints, specifically addressing CWE-306 and CWE-290, to prevent unauthenticated access to critical functions and bypasses via spoofed user-agent headers.
Limits and watch
The CVSS score is 8.6, but the attack requires no network access, limiting the threat to systems where authentication is already enabled. The extent of JADEPUFFER’s autonomous decision-making beyond the documented Azure and Langflow exploitation remains unclear, as the evidence confirms specific destructive actions but not the full scope of the agent’s capabilities. The specific mechanisms for pivoting into production environments beyond the initial Langflow entry point are not fully detailed in the available evidence. Watch for unusual generative AI activity in reconnaissance or payload creation, since attackers may use large language models to automate phishing or script writing in ways that are hard to spot from outside the target network.
Vulnerabilities
- CVE-2025-3248 — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.
- CVE-2021-29441 — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.
Techniques
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0010.001 AI Software (Initial Access)
- AML.T0016.002 Generative AI (Resource Development)
- AML.T0053 AI Agent Tool Invocation (Execution)
- AML.T0054 LLM Jailbreak (Defense Evasion)
- AML.T0090 OS Credential Dumping (Credential Access)
- AML.T0098 AI Agent Tool Credential Harvesting (Credential Access)
- AML.T0102 Generate Malicious Commands (Ai Attack Staging)
- AML.T0108 AI Agent (Command And Control)
- T1059.009 Cloud API (Execution)
- and 4 more
Indicators
- 3 indicators on file
Coverage
- JADEPUFFER: First End-to-End AI-Driven Ransomware Operation
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
- This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
- JadePuffer ransomware used AI agent to automate entire attack
- JadePuffer agentic attacks now target AI model data with ransomware
- Smooth AI criminal drives ‘first’ end-to-end agentic ransomware attack
-
[CISA Adds One Known Exploited Vulnerability to Catalog CISA](https://cisa.gov/news-events/alerts/2025/05/05/cisa-adds-one-known-exploited-vulnerability-catalog) - JadePuffer returns with ransomware built to target AI models and infrastructure - Help Net Security
6. AI Agent Chains Zammad Zero-Days to Breach DIVD (Segment)
Event first seen in a show
What changed
On September 21, 2026, an autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two zero-day vulnerabilities in its Zammad ticketing system. The attack exploited CVE-2026-102489 and CVE-2026-102490 to hijack sessions, execute remote code, and escalate privileges to root within seconds. This allowed it to exfiltrate email addresses and contact details belonging to DIVD’s volunteer security researchers. There is slight ambiguity regarding the exploitability of CVE-2026-102489 in certain environments, but the compromise of researcher data is solid. The stolen contact data now poses a direct social engineering risk to DIVD staff. Detection engineers should immediately review Zammad logs for anomalous session material or cookie patterns in error output, using the verification script DIVD published. Six independent outlets, including BleepingComputer and Help Net Security, confirmed the breach vector and specific CVEs involved. If you run Zammad versions 7.0.0 through 7.1.3, upgrade to version 7 or take the system offline now.
How it works
The agent then leveraged CVE-2026-102490 to escalate privileges from the local zammad user to root, completing the attack chain. This exploit chain bypasses standard access controls, allowing an adversary to gain root privileges without prior authentication. Attackers can hijack Zammad sessions in versions 6.3.0 through 6.5.4 to run remote code as the zammad user, while versions 7.0.0 to 7.1.3 remain unexploitable due to missing environment conditions. Network segmentation prevented further lateral movement, and DIVD has since notified affected parties while actively scanning for other vulnerable Zammad instances. The compromise of DIVD’s Zammad instance via CVE-2026-102489 and CVE-2026-102490 confirms unpatched helpdesk systems expose root-level access to autonomous agents.
What to do
This privilege escalation targets the Zammad service stack, creating direct root compromise for operators running versions 1.5.0 to 7.1.0-alpha. Any instance in that range faces immediate root compromise risk if the local zammad user is compromised. Operators must patch Zammad immediately for versions 6.3.0 through 6.5.4 today, as the 7.0.0 to 7.1.3 range offers no immediate mitigation despite the vulnerability presence. Run the DIVD-published shell script against /var/log/zammad and /var/log/nginx to identify exposed cookies or session material in error output.
Limits and watch
CVE-2026-102489 exists in Zammad versions 7.0.0 through 7.1.3, but specific conditions prevent exploitation, limiting immediate remote code execution risk for that range. The specific data exfiltrated from DIVD remains undisclosed, leaving the full scope of compromised researcher contact details and potential social engineering targets uncertain. Watch for abnormal LSASS memory access or unexpected crashes in authentication services, as these indicate exploitation of credential validation processes. Correlate failed or anomalous PAM authentications with subsequent successful unauthorized logins to identify privilege escalation tied to credential service exploitation.
Vulnerabilities
- CVE-2026-102489 — CVSS 0 (Low) · Zammad GmbH Zammad. Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user.
- CVE-2026-102490 — CVSS 0 (Low) · Zammad GmbH Zammad. All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Techniques
- AML.T0086 Exfiltration via AI Agent Tool Invocation (Exfiltration)
- AML.T0108 AI Agent (Command And Control)
- AML.T0112 Machine Compromise (Impact)
- T1068 Exploitation for Privilege Escalation (Privilege Escalation)
- T1110.003 Password Spraying (Credential Access)
- T1212 Exploitation for Credential Access (Credential Access)
- T1589.002 Email Addresses (Reconnaissance)
- T1684 Social Engineering (Stealth)
Indicators
- 1 indicator on file
Coverage
- Zammad Zero-Days Exploited in AI-Powered DIVD Hack
- AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
- DIVD says Zammad zero-days enabled AI-driven network breach
- AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
- log check script
- DIVD-2026-00014 - When, not if…
- Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
- AI agents hacked the hackers, stealing email addresses from security research org
- Undisclosed RCE in Zammad v6.3 and higher
- Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
- Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
7. ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities, FBI, and Nissan (Segment)
Event now covered by 2 outlets (was 1); 1 new indicator(s) observed
What changed
ShinyHunters is actively exploiting a critical zero-day in Oracle PeopleSoft, compromising over one hundred organizations including the FBI and Nissan Americas. The group, tracked as UNC6240, leveraged CVE-2026-35273, an unauthenticated remote code execution flaw in PeopleTools versions 8.61 and 8.62. This campaign ran from May 27 to June 9, 2026. While the FBI’s job portal remains offline, Nissan confirmed the exposure of Social Security numbers and banking details for employees in the US, Canada, Mexico, and Brazil. ShinyHunters has launched a new wave of attacks against agriculture, government, and healthcare organizations, claiming to have compromised personal information of FBI employees. Google’s Mandiant and Threat Intelligence Group report that the group used a new technique to target PeopleSoft servers that had not applied security updates. The FBI confirmed it is investigating ShinyHunters’ claim of having compromised personal information of its employees. ShinyHunters leveraged an unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach portals. Attackers deployed web shells by targeting exposed Environment Management Hub endpoints, using URL-encoding to bypass WAF protections. Reports are consistent on the vulnerability and the WAF bypass technique, though some outlets differ on whether the initial target was strictly higher education or a broader mix of sectors. You need to check if your PeopleSoft instances are exposed and verify that WAF rules account for percent-encoded or mixed-case variants of the PSEMHUB endpoint. Watch for connections to attacker infrastructure domains like azurenetfiles[.]net or IPs 142[.]11[.]200[.]186 and 162[.]219[.]30[.]165. The lead sheet details the full IOC set and the specific WAF evasion patterns.
How it works
The weakness, rated a CVSS 9.8, requires no authentication or network interaction to succeed, meaning any HTTP-accessible instance becomes an immediate takeover target. Specifically, this enables immediate takeover of the Oracle Concurrent Processing service without any prior access precondition. UNC6240 modified its exploit to bypass web application firewall rules blocking the vulnerable Environment Management Hub endpoint. Threat actors used percent-encoded, mixed-case, or otherwise non-normalized variants of the /PSEMHUB/ path to evade detection. The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest, with the University of Nottingham being one of the first confirmed victims.
What to do
The FBI is investigating ShinyHunters’ claim of compromising employee personal information, elevating the threat from a corporate breach to a national security incident. Unlike the other CVE in this set, this specific flaw targets the Updates Environment Management subsystem, forcing operators to isolate PeopleSoft 8.61 and 8.62 immediately while waiting for the official fix. While the broader event includes CVE-2026-35273, this specific flaw stands out because its unauthenticated nature means defenders must immediately isolate affected Oracle E-Business Suite instances to prevent remote takeover. Because UNC6240 modified its exploit to bypass WAF rules by using percent-encoded or mixed-case variants of the PSEMHUB endpoint, standard signature-based filtering is no longer sufficient to protect exposed PeopleSoft servers. Apply the Oracle Emergency Security Update immediately to remediate CVE-2026-35273 in PeopleSoft PeopleTools versions 8.61 and 8.62, as the advisory confirms the vulnerability is remotely exploitable without authentication. Update WAF configurations to explicitly block non-normalized, percent-encoded, and mixed-case variants of the /PSEMHUB/ endpoint to prevent the specific bypass technique used by UNC6240.
Limits and watch
Reports conflict on whether the initial target set was strictly higher education or a broader mix of agriculture, government, and healthcare, which complicates the assessment of which sectors are currently at highest risk. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters, which indicates web shell deployment for persistent access.
Vulnerabilities
- CVE-2025-61882 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation Oracle Concurrent Processing. Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).
- CVE-2026-35273 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).
Techniques
- AML.T0000 Search Open Technical Databases (Reconnaissance)
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0049 Exploit Public-Facing Application (Initial Access)
- AML.T0050 Command and Scripting Interpreter (Execution)
- AML.T0055 Unsecured Credentials (Credential Access)
- AML.T0072 Reverse Shell (Command And Control)
- T1005 Data from Local System (Collection)
- T1016 System Network Configuration Discovery (Discovery)
- T1018 Remote System Discovery (Discovery)
- T1027 Obfuscated Files or Information (Stealth)
- and 10 more
Named actors and malware
- ShinyHunters (actor)
- Neo-reGeorg (malware)
- Umbreon (malware)
- TeamPCP (actor)
- Umbreon. (malware)
Indicators
- 23 indicators on file
Coverage
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
- Oracle Security Alert Advisory - CVE-2026-35273
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
- Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters
- Oracle Emergency Security Update to Fix Critical RCE Vulnerability
- ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters
- Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks
- FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
- FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
8. Apple patches CoreGraphics zero-day exploited in targeted attacks (Segment)
5 new indicator(s) observed
What changed
On September twenty-eighth, Apple pushed emergency updates for iOS 26.7.1, iPadOS 26.7.1, and macOS to patch CVE-2026-86950, a zero-day vulnerability in the CoreGraphics framework. Reported by Meta Product Security, this out-of-bounds write flaw allows arbitrary code execution when the system processes maliciously crafted files. CISA has added the bug to its Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. Although researchers at Califio have published a proof-of-concept, the technical details remain sparse. If you see a device that hasn’t updated after the September twenty-eighth release, isolate it now. Apple confirmed that CVE-2026-86950 may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions prior to iOS 27.
How it works
The vulnerability resides in the CoreGraphics component, where an out-of-bounds write occurs during the processing of maliciously crafted files, potentially PDFs with embedded fonts. This memory safety issue allows an attacker to execute arbitrary code on the device, a capability that Apple addressed in the patch by implementing improved bounds checking. The attacker leveraged this weakness by processing a maliciously crafted file to trigger the improved bounds checking failure, resulting in arbitrary code execution with a CVSS score of 8.8. The vulnerability stems from a memory corruption issue where an attacker with write capability can execute arbitrary code by exploiting improved state management flaws. The patch applies to iPhone 11 and later, iPad Pro models, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later.
What to do
The CVSS score of 7.8 indicates high severity, yet attackers need only minimal privileges to trigger the exploit on affected Apple platforms. Because the flaw enables arbitrary code execution when processing malicious files, any unpatched device in your fleet represents a direct entry point for the sophisticated targeted attacks Apple has already confirmed. Apple declined to provide further details regarding the victims or the nature of the attacks, and researchers have not disclosed the full exploit chain. This uncertainty means we cannot confirm the exact delivery vector, though the PoC suggests WhatsApp could serve as a vector for the malicious file. The framework-to-behavior connection here is that T1203, Exploitation for Client Execution, relies on the user action of opening the file, which aligns with T1204.002, Malicious File. The most useful investigation focus is enabling T1203 mitigation option 1, Application Isolation and Sandboxing, and T1203 mitigation option 2, Exploit Protection, to detect and block conditions indicative of software exploits. Additionally, enable T1204.002 mitigation option 1, Behavior Prevention on Endpoint, and T1204.002 mitigation option 2, Execution Prevention, to block unauthorized code execution and monitor for anomalous patterns indicative of the exploit. The watch item is a signal of unpatched iOS devices before iOS 27 that have processed PDF files recently, as this is the only concrete signal supported by the evidence. Update all managed devices to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 immediately to close the CoreGraphics vulnerability and stop arbitrary code execution. Isolate any device that has not yet received the September twenty-eighth emergency patch, as these systems remain exposed to the specific targeted attack vectors described in the advisory.
Limits and watch
While the out-of-bounds write in CoreGraphics is confirmed, the specific file types and delivery mechanisms used in the targeted attacks remain sparse in the available technical details. The scope of exploitation is currently limited to specific targeted individuals on iOS versions prior to iOS 27, meaning the full extent of compromise across your broader user base is not yet established. Watch for client application crashes or abnormal exits in CoreGraphics-dependent processes, as these indicate potential exploitation attempts against the unpatched vulnerability.
Vulnerabilities
- CVE-2026-86950 — CVSS 8.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS. An out-of-bounds write issue was addressed with improved bounds checking.
- CVE-2026-20700 — CVSS 7.8 (High) · CISA KEV · Apple iOS and iPadOS; Apple macOS; Apple tvOS. A memory corruption issue was addressed with improved state management.
Techniques
- T1203 Exploitation for Client Execution (Execution)
- T1204.002 Malicious File (Execution)
- T1213.005 Messaging Applications (Collection)
Indicators
- 6 indicators on file
Coverage
- Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
- About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support
- Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks
- Apple patches CoreGraphics zero-day already exploited in targeted attacks
- Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
- CISA Adds One Known Exploited Vulnerability to Catalog
- publications/MADBugs/CVE-2026-86950 at main · califio/publications
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- CVE-2026-86950: The Great Glyph Grift
- Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
9. CISA adds AI-discovered BeyondTrust RCE to KEV as Google reports vulnerability disclosures double (Segment)
No material change since last show
What changed
Threat actors exploited this flaw within four days of public disclosure, using malware such as SNOWLIGHT to exfiltrate data. This follows a Google Threat Intelligence Group report showing AI-assisted discovery has doubled monthly vulnerability disclosures to over ten thousand, with a significant rise in high-severity remote code execution flaws. Associated MITRE techniques include Exploitation of Remote Services and Remote Access Tools. While core facts are solid across five independent outlets, including CISA and The Record, specific malware families are reported with varying detail. Hacktron AI research agent autonomously identified a vulnerability that lets unauthenticated attackers execute OS commands directly on the host. BeyondTrust patched cloud deployments in early February 2026, yet approximately eleven thousand internet-facing instances remain exposed. CISA and The Record corroborated the vulnerability and its active exploitation, though specific malware families are reported with varying detail. Your SOC must immediately identify any exposed BeyondTrust instances in your perimeter.
How it works
Today, BeyondTrust Remote Support and Privileged Remote Access versions zero allow unauthenticated attackers to inject commands as site users via command injection. The flaw stems from improper neutralization of special elements when the software constructs commands using externally influenced input. An unauthenticated attacker sends specially crafted requests to the BeyondTrust application, which fails to neutralize special elements in the input, allowing the injection of operating system commands. The injected commands execute in the context of the site user, granting the attacker remote code execution capabilities without requiring prior authentication or user interaction. A critical pre-authentication flaw allows remote attackers to execute site user commands, bypassing standard access controls. This vulnerability carries a CVSS score of 9.8, granting full integrity and unauthorized code execution.
What to do
CISA added CVE-2026-1731 to the Known Exploited Vulnerabilities catalog, making the unauthenticated remote code execution flaw in BeyondTrust Remote Support and Privileged Remote Access an active federal compliance requirement under Binding Operational Directive 22-01. Patch BeyondTrust RS and PRA immediately to stop remote code execution before the next attack wave arrives. Identify and patch all self-hosted BeyondTrust Remote Support and Privileged Remote Access instances to versions 25.3.2 and 25.1.1 or later, as cloud deployments were already remediated on February 2, 2026. Prioritize network segmentation for any remaining unpatched instances to prevent unauthenticated attackers from reaching the remote service ports that enable command injection. Validate all external inputs against known good lists and avoid dynamic command construction until patches arrive. Verify static analysis scans for command construction and block control characters in incoming remote session data immediately. Isolate affected systems and apply the architecture and design mitigation to prevent unauthorized code execution. Assume all remote input is malicious and switch to static command construction to stop the command injection attack pattern.
Limits and watch
Static analysis tools can detect this weakness, but we cannot confirm a patch date for the affected products yet. The specific malware families involved in the active exploitation of CVE-2026-1731 are reported with varying detail across sources, making it difficult to confirm a single consistent payload signature for detection. While both CVE-2024-12356 and CVE-2026-1731 share a CVSS score of 9.8 and pre-authentication access requirements, the exact version ranges affected by the older CVE-2024-12356 are not clearly distinguished from the newer flaw in the provided evidence. Watch for repeated detection of control characters by input filters, as this specific indicator signals an attempt to exploit multiple input interpretation layers in the remote service.
Vulnerabilities
- CVE-2024-12356 — CVSS 9.8 (Critical) · CISA KEV · CWE-77 · BeyondTrust Remote Support; BeyondTrust Privileged Remote Access. A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
- CVE-2026-1731 — CVSS 9.8 (Critical) · CISA KEV · CWE-78 · BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA). BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability.
Techniques
- AML.T0001 Search Open AI Vulnerability Analysis (Reconnaissance)
- AML.T0010.005 AI Agent Tool (Initial Access)
- AML.T0016.002 Generative AI (Resource Development)
- AML.T0103 Deploy AI Agent (Execution)
- T1203 Exploitation for Client Execution (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1219 Remote Access Tools (Command And Control)
- T1588.007 Artificial Intelligence (Resource Development)
Coverage
- CVE-2026-1731: Pre-Auth RCE in BeyondTrust Remote Support & PRA
- Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
- AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
-
[CISA Adds One Known Exploited Vulnerability to Catalog CISA](https://cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog) - Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
- BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) - Help Net Security
10. ThreatCluster Launches Free Threat Intelligence API (Segment)
Event first seen in a show
What changed
A new wave of piano scams is currently targeting humans as the primary vector of attack. ThreatCluster just opened its doors to the public with a new REST API. The data refreshes within minutes of credible reports and supports STIX 2.1 output, making it ready for integration with tools like Splunk, Sentinel, and MCP clients. While the core API launch is well-documented by both ThreatCluster and Inoreader, other recent podcast discussions touched on disparate topics like piano scams and Kraken targeting Israel. The confirmed threat landscape includes Kraken targeting Israel and cybersecurity companies installing operations in Kyiv.
How it works
Adversaries use generative AI tools to draft phishing content and automate malicious script creation. They search social media platforms to harvest victim information for building fake profiles that elicit further data. ThreatCluster provides a REST API with over seventy endpoints that allows users to query ransomware victims and STIX objects using daily credits. The Recorded Future News podcast series covers cybersecurity topics including ransomware, space security, and the use of AI in law enforcement. ThreatCluster’s new REST API provides free, STIX 2.1-compliant access to 70+ endpoints for incidents and CVEs, enabling direct integration with SIEMs and SOARs without OAuth or installation. This capability allows defenders to automate the ingestion of threat data, reducing the manual effort required to correlate external intelligence with internal detection logic. Attackers can now rapidly identify specific staff members to target with personalized disinformation or credential harvesting, creating a high-priority need to audit public footprints and restrict access to sensitive internal announcements. While the new API allows integration with Splunk or Sentinel to track these threats, the uncertainty remains that attackers will continue to use AI to refine their targeting strategies. The most useful investigation focus is monitoring for automated patterns of social media scraping or impersonation attempts rather than waiting for confirmed compromises.
What to do
Configure your SIEM or SOAR to query ThreatCluster’s endpoints using the X-API-Key to automatically ingest STIX 2.1 objects for ransomware victims and threat actors like LockBit.
Limits and watch
The evidence packet does not confirm specific operational impacts of the ThreatCluster API on current threat actor behaviors, only its technical capabilities and integration features. Uncertainty remains regarding the specific false positive rates associated with detecting social media reconnaissance, as much of this activity occurs outside the target organization’s visibility. Watch for spikes in phishing attempts that show signs of AI generation, like multilingual drafting or better obfuscation.
Techniques
- T1001.003 Protocol or Service Impersonation (Command And Control)
- T1005 Data from Local System (Collection)
- T1008 Fallback Channels (Command And Control)
- T1010 Application Window Discovery (Discovery)
- T1012 Query Registry (Discovery)
- T1016 System Network Configuration Discovery (Discovery)
- T1021.001 Remote Desktop Protocol (Lateral Movement)
- T1021.002 SMB/Windows Admin Shares (Lateral Movement)
- T1021.004 SSH (Lateral Movement)
- T1027.007 Dynamic API Resolution (Stealth)
- and 10 more
Named actors and malware
- LockBit (malware)
- Lazarus group (actor)
Indicators
- 1 indicator on file
Coverage
-
[Threat intelligence REST API ThreatCluster](https://threatcluster.io/api) - How AI can debunk a conspiracy theory in 8 minutes
- How Bellingcat finds the truth in the age of AI