CISA warns of active exploitation of critical infrastructure flaws

Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.

12 reports · 10 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. https://www. bleepingcomputer.com/news/secu

mastodon:infosec-exchangeother15d ago kagi ↗

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. https://www. bleepingcomputer.com/news/secu rity/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/

🤖 CISA warns CVE-2026-85706, a max-severity GitLab flaw, is now exploited in the wild. Missing auth + path confinement in the commits API lets unauthenticated attackers read credentials/secrets in a

mastodon:infosec-exchangeother15d ago kagi ↗

🤖 CISA warns CVE-2026-85706, a max-severity GitLab flaw, is now exploited in the wild. Missing auth + path confinement in the commits API lets unauthenticated attackers read credentials/secrets in a single HTTP request. watchTowr observed in-the-wild probing. Fixed in CE/EE 19.3.2, 19.2.6, 19.1. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-hackers-now-exploit-max-severity-gitlab-flaw-

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched

mastodon:infosec-exchangeother14d ago kagi ↗

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/

"CISA: Critical VMware RCE flaw now exploited by ransomware gangs" "[...] Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing at

mastodon:infosec-exchangeother14d ago kagi ↗

"CISA: Critical VMware RCE flaw now exploited by ransomware gangs" "[...] Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. The U.S." https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-g

🤖 CVE-2026-59310: critical directory traversal in VMware vCenter Syslog server, unauthenticated RCE. Patched Jul 29, exploited in the wild, CISA KEV now flags active abuse by ransomware gangs. ~450 v

mastodon:infosec-exchangeother14d ago kagi ↗

🤖 CVE-2026-59310: critical directory traversal in VMware vCenter Syslog server, unauthenticated RCE. Patched Jul 29, exploited in the wild, CISA KEV now flags active abuse by ransomware gangs. ~450 vCenter servers still exposed. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/ # CVE # Ransomware # CyberSec

🤖 CISA: ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter RCE patched in July. Unpatched vCenter instances remain a prime entry point — patch now and audit exposed

mastodon:infosec-exchangeother14d ago kagi ↗

🤖 CISA: ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter RCE patched in July. Unpatched vCenter instances remain a prime entry point — patch now and audit exposed hosts. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/ # VMware # Ransomware # CVE # CyberSec