Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.
12 reports · 10 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. https://www. bleepingcomputer.com/news/secu rity/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/
🤖 CISA warns CVE-2026-85706, a max-severity GitLab flaw, is now exploited in the wild. Missing auth + path confinement in the commits API lets unauthenticated attackers read credentials/secrets in a single HTTP request. watchTowr observed in-the-wild probing. Fixed in CE/EE 19.3.2, 19.2.6, 19.1. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-hackers-now-exploit-max-severity-gitlab-flaw-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
"CISA: Critical VMware RCE flaw now exploited by ransomware gangs" "[...] Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. The U.S." https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-g
🤖 CISA: ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter RCE patched in July. Unpatched vCenter instances remain a prime entry point — patch now and audit exposed hosts. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/ # VMware # Ransomware # CVE # CyberSec