On 2026-09-27 and 2026-09-28, CERT-EU and CERT-Bund (BSI) issued critical security advisories for Citrix NetScaler ADC and Gateway products, reporting remote code execution vulnerabilities. Additional high-severity flaws in Budibase, QEMU, ESRI ArcGIS, and Kiteworks were also published during this period.
RE: https:// infosec.exchange/@mttaggart/11 7343778122030020 Literally as I'm typing this Citrix releases their advisory: https:// support.citrix.com/support-hom e/kbsearch/article?articleNumber=CTX697096
Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway products are being actively exploited as of late September 2026, including CVE-2026-88771 (command injection) and CVE-2026-19490 (SAML authentication bypass). Citrix released security bulletins and patches are available.
Citrix released patches on September 27, 2026, for two critical remote-code-execution zero-day flaws (CVE-2026-88771, CVE-2026-88772) in NetScaler ADC and Gateway that researchers confirmed are being exploited globally. CISA set a deadline for organizations to apply updates.
"Citrix admins warned to shut down NetScalers over 2 exploited zero-days" "" https://www.
Spanish-language social posts from 2026-08-27 to 2026-08-29 sharing links to tech and security news: TranslatePress vulnerability affecting 400,000 sites, Claude Opus gym booking flaw, FBI takedown of Chinese QTFY infrastructure, Photoshop AI features, Ubuntu LTS, and Gitea server exposures.
Hackers explotan vulnerabilidad crítica de SSRF en MLflow https:// blog.elhacker.net/2026/08/hack ers-explotan-vulnerabilidad-critica.html
Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.
Citrix issued an urgent security warning on August 20, 2026, regarding two vulnerabilities affecting NetScaler Gateway and NetScaler ADC networking appliances, including at least one critical unauthenticated flaw. The company urged administrators to patch systems immediately.
Microsoft patentará IA para crear historias de videojuegos https:// blog.elhacker.net/2026/09/micr osoft-patentara-ia-para-crear.html
The Cybersecurity and Infrastructure Security Agency issued orders over the weekend of 28 September 2026 directing all US government agencies to patch two critical Citrix NetScaler vulnerabilities by Wednesday. The flaws are being actively exploited in attacks.
Two unpatched remote-code-execution zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) in Citrix NetScaler ADC and Gateway are being actively exploited in attacks as of September 27, 2026. CISA and the Dutch NCSC recommend immediate patching; some IT providers recommend shutting down affected appliances.
exchange/@watchTowr/11 7338396418850285 We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix.
Citrix urges admins to patch new NetScaler flaws as soon as possible https://www.
A collection of social media posts on September 28–29, 2026, referencing various cybersecurity topics including AI agent governance, cryptocurrency hacks, Citrix exploits, MCP Python SDK vulnerabilities, and Facebook privacy litigation. No coherent single story emerges.
Citrix released patches for CVE-2026-19490, a critical authentication bypass flaw (CVSS 9.3) in NetScaler ADC and NetScaler Gateway, by August 20, 2026, after the vulnerability was actively exploited by unauthenticated attackers. The flaw allows remote attackers to bypass authentication controls via an alternate path.
🚨🐛 SIGINT // Cybersecurity Watch — 2026-08-30 Attackers chain two PaperCut flaws for pre-auth RCE; active exploitation confirmed with patch bypasses discovered.