TL;DR for CISOs: Citrix confirmed that two critical, unauthenticated remote-code-execution flaws in NetScaler ADC and Gateway were exploited in the wild before patches were available, and warned that "updating alone did not remove the risk" of prior compromise. CISA separately added a Microsoft SharePoint code-injection flaw and a chained MikroTik RouterOS authentication-bypass pair to its Known Exploited Vulnerabilities catalog. Kiteworks told customers worldwide to take servers offline over the weekend after federal intelligence authorities warned of a possible imminent zero-day attack. And Singapore telco Simba disclosed a breach affecting more than 23,500 customers, now under regulator investigation.
- Patching a zero-day does not close the incident. Citrix itself said "updating alone did not remove the risk" from the NetScaler flaws, because attackers who already got in before the patch shipped can persist through credentials, sessions and certificates issued during the exposure window. Treat "patched" and "no longer at risk" as two separate questions.
- Vendors are starting to get advance warning from government sources before any public exploitation is confirmed. Kiteworks shut down systems worldwide on a federal tip with no confirmed breach. If your vendors ever call you with a similar warning, your incident-response plan needs a lane for "act on a credible warning" that doesn't require proof of compromise first.
- Two more products, SharePoint and MikroTik RouterOS, joined the growing list of everyday enterprise infrastructure under active attack this week. None of today's technical flaws are exotic; all are patchable. The gap between "patch available" and "patch applied" is still where most of this damage happens.
Lead story: Two Citrix NetScaler zero-days were exploited before patches existed
CRITICAL · ACTIVELY EXPLOITEDCVE-2026-88771 (CVSS 9.5): improper input validation in NetScaler ADC and NetScaler Gateway allowing unauthenticated remote code execution on all deployments
CVE-2026-88772 (CVSS 9.5): a memory overflow causing RCE or denial of service on appliances with DTLS enabled, the default configuration for VPN virtual servers
Affected versions: NetScaler ADC and Gateway 14.1 builds before 14.1-73.37, and 13.1 builds before 13.1-64.23
Discovery and disclosure: security firm watchTowr disclosed the flaws on September 26, 2026; Citrix confirmed active exploitation of unpatched deployments in its September 27 security bulletin, without specifying when exploitation began
Also patched: six additional NetScaler flaws, CVE-2026-88773 through CVE-2026-88778, CVSS 7.0 to 9.3, with no evidence of exploitation reported for those six
Remediation guidance: Citrix said "updating alone did not remove the risk" of prior compromise and recommended credential resets, certificate revocation and forensic investigation on any appliance that was internet-exposed and unpatched
What happened
Citrix confirmed on September 27 that two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, were being exploited in the wild against unpatched appliances, and that both were used by attackers before public patches existed. Security firm watchTowr disclosed the flaws a day earlier, on September 26. CVE-2026-88771 is an improper input validation issue that allows an unauthenticated attacker to execute arbitrary code on any NetScaler ADC or Gateway deployment; CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service specifically on appliances with DTLS enabled, which is the default state for VPN virtual servers, a very common production configuration.
Citrix released fixes covering NetScaler ADC and Gateway 14.1 builds prior to 14.1-73.37 and 13.1 builds prior to 13.1-64.23, alongside six other patched flaws, CVE-2026-88773 through CVE-2026-88778, ranging from CVSS 7.0 to 9.3, for which the company has not reported evidence of exploitation. Citrix has not disclosed how long the two exploited flaws were being used in attacks before its bulletin, only that exploitation predated the availability of patches.
NetScaler appliances sit at the network edge, handling VPN access and application delivery for internet-facing traffic, which is precisely why they are a recurring, high-value target: a compromised appliance can give an attacker an initial foothold without needing to touch an endpoint first. Citrix's own guidance underlines that point, explicitly warning that installing the patch does not by itself remove risk for any deployment that was already compromised.
Evidence
Verified against independently fetched sources:
1. The Hacker News, "Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation," September 27, 2026
2. BleepingComputer, "Citrix admins warned to shut down NetScalers over 2 exploited zero-days," September 27, 2026
What this means for your team
Treat every unpatched, internet-exposed NetScaler appliance as a probable prior-compromise case, not just a patching gap. Citrix's own advice, that "updating alone did not remove the risk," is the operative instruction here: a credential rotation and certificate revocation exercise belongs in your remediation plan alongside the patch itself, on any appliance that was exposed before you applied the fix.
The fact that DTLS, a default setting for VPN virtual servers, is directly implicated in one of the two flaws is worth flagging to whoever owns your VPN infrastructure specifically, since a default configuration choice is now part of the exploited attack surface rather than an edge case.
Six additional patched NetScaler flaws with no confirmed exploitation yet are still worth patching on the same cycle. A CVSS 9.3 flaw with no current exploitation evidence is a matter of time, not safety, based on this platform's history as a repeat target.
- Patch all NetScaler ADC and Gateway deployments to 14.1-73.37, 13.1-64.23 or later immediately, including the six additional flaws Citrix disclosed in the same bulletin.
- For any appliance that was internet-exposed and unpatched at any point, treat it as potentially already compromised: rotate all credentials and tokens, revoke and reissue certificates, and run a forensic review of configuration and session logs rather than closing the ticket at "patched."
- If DTLS is enabled on your VPN virtual servers, confirm it is patched against CVE-2026-88772 specifically, since that is the default configuration the flaw targets.
- Where immediate patching is not possible, reduce internet-facing exposure of the management and VPN interfaces and add monitoring for anomalous authentication and configuration-change activity in the interim.
CISA adds actively exploited SharePoint and MikroTik router flaws to its watchlist
HIGH · ACTIVELY EXPLOITEDCVE-2026-65660 (CVSS 8.8): a code-injection flaw in Microsoft Office SharePoint that permits an authenticated attacker to execute code over the network
CVE-2026-67279 (CVSS 6.9): a MikroTik RouterOS flaw that, chained with CVE-2026-86060, gives full unauthenticated access to the administrative console on internet-exposed routers, a combination researchers have dubbed "MikroTrick"
Confirmation: Microsoft confirmed reliable evidence of observed attacks against the SharePoint flaw as of September 25, 2026; security firm Bishop Fox confirmed complete administrative takeover is achievable on vulnerable RouterOS 7.x builds using the chained MikroTik flaws
CISA action: both CVEs were added to the Known Exploited Vulnerabilities catalog on September 27, 2026, with a federal civilian agency patching deadline of September 28, 2026
Disclosure gap: Microsoft has not disclosed attacker identity, attack scope or post-compromise activity for the SharePoint flaw
What happened
CISA added two unrelated but simultaneously catalogued vulnerabilities to its Known Exploited Vulnerabilities list on September 27: a Microsoft SharePoint code-injection flaw, CVE-2026-65660, and a MikroTik RouterOS authentication-bypass chain, CVE-2026-67279 combined with CVE-2026-86060. Microsoft says it has reliable evidence of attacks against the SharePoint flaw as of September 25 but has not disclosed who is behind them, how many organizations are affected, or what attackers did after gaining code-execution access.
The MikroTik pair is more fully documented. Researchers at Bishop Fox demonstrated that chaining the two flaws together defeats every authentication requirement on the router's administrative console, giving an attacker complete administrative takeover on vulnerable RouterOS 7.x builds. Because the two individual bugs each represent a separate trust-boundary failure, patching only one leaves the chain, and the takeover it enables, intact.
Binding Operational Directive 26-04 requires federal civilian agencies to remediate both by September 28, 2026, one day after the catalog addition. CISA's standard language framing catalog additions as a "frequent attack vector for malicious cyber actors" applies to both entries, and the agency recommends all organizations, not just federal ones, prioritize these two regardless of the directive's narrower legal scope.
Evidence
Verified against independently fetched sources:
1. CISA, "CISA Adds Two Known Exploited Vulnerabilities to Catalog," bulletin dated September 27, 2026
2. The Hacker News, "SharePoint RCE and MikroTik RouterOS Flaws Added to CISA's Known Exploited Vulnerabilities Catalog"
What this means for your team
Chained vulnerabilities like the MikroTik pair are a reminder that a single-CVE patch tracker can create false confidence: if you patch CVE-2026-67279 but miss CVE-2026-86060, or the reverse, the full-takeover chain still works. Confirm your patch management process closes both halves of a disclosed chain, not just the CVE that made the headline.
The SharePoint flaw's thin public detail, no attacker attribution, no confirmed scope, is itself a signal: Microsoft's confirmation that attacks are occurring is enough reason to patch now, without waiting for a fuller incident writeup that may not arrive for weeks.
- Patch on-premises SharePoint servers against CVE-2026-65660 immediately; treat any unpatched, internet-reachable instance as a live target given Microsoft's confirmation of observed attacks.
- If you run MikroTik RouterOS, confirm you have addressed both CVE-2026-67279 and CVE-2026-86060; patching only one leaves the documented full-takeover chain intact.
- Audit internet-facing RouterOS administrative interfaces and restrict management access to trusted networks regardless of patch status, since router takeovers are a common pivot point into broader network compromise.
- Confirm your vulnerability management workflow tracks CISA KEV additions as a distinct, higher-urgency queue rather than folding them into routine patch cycles, given the September 28 federal deadline attached to both entries.
Kiteworks told customers worldwide to shut down servers over a federal zero-day warning
HIGH · PRECAUTIONARY SHUTDOWNWho: Kiteworks, formerly Accellion, an enterprise secure file-transfer and content-collaboration vendor
Warning source: credible threat intelligence from federal intelligence authorities, agency not named, indicating a threat actor may attempt to target some Kiteworks customer systems
Action taken: Kiteworks recommended a precautionary shutdown window applied globally by time zone; in Central Europe, customers were told to take systems offline from 4:00 a.m. to 10:00 a.m. on Saturday, September 26, a roughly six-hour window, with some reporting describing the overall global window as up to nine hours
Confirmed exploitation: none; Kiteworks and its CISO, Frank Balonis, both stated this was a preventative measure, not a response to confirmed compromise
Patch status: Kiteworks says all known vulnerabilities are addressed in its current release, 9.5.1, and recommends customers run that version
Scope: Kiteworks said subsidiary products, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder, were unaffected by the warning
History: Kiteworks' predecessor product was the target of the Clop group's 2020 to 2021 zero-day campaign against file-transfer software, a pattern this warning echoes without yet confirming a repeat
What happened
Kiteworks CISO Frank Balonis issued an advisory urging customers to take Kiteworks systems offline for a precautionary window over the weekend of September 26 to 27, after what the company described as credible threat intelligence from federal intelligence authorities indicating a threat actor might target some Kiteworks systems. The company did not name the agency or the suspected threat actor, and stated explicitly that no customer compromise had been confirmed; the shutdown was framed as preventative rather than reactive.
The window varied by region and by which outlet's timing was reported: Kiteworks' own Central European guidance specified 4:00 a.m. to 10:00 a.m. on Saturday, September 26, a six-hour window, while some coverage described the overall global rollout as spanning up to nine hours across time zones. Kiteworks said all known vulnerabilities are addressed in its current release, version 9.5.1, and recommended customers confirm they are running it regardless of whether they took part in the shutdown.
The episode inevitably recalls Kiteworks' history under its former name, Accellion, whose file-transfer product was the target of a zero-day campaign attributed to the Clop group in 2020 and 2021 that led to significant downstream data breaches at Accellion customers. Kiteworks has not confirmed whether this warning relates to a genuine zero-day in its own product, a supply-chain concern, or a broader sector-wide alert; as of publication, no exploitation of any Kiteworks system has been confirmed.
Evidence
Verified against independently fetched sources:
1. BleepingComputer, "Kiteworks urges 6-hour server shutdown over potential zero-day attacks," September 25, 2026
2. The Hacker News, "Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack," September 26, 2026
What this means for your team
A vendor being handed threat intelligence by a federal agency, before any exploitation is confirmed, is still an unusual pattern, and it is worth asking your own critical vendors whether they have a defined process for acting on that kind of warning rather than waiting for proof of compromise. If your organization uses Kiteworks or any file-transfer and content-collaboration platform, this is a reasonable moment to confirm your own version, patch status and exposure independent of whether you took part in the shutdown window.
File-transfer software's history as a repeated target, this incident echoes the earlier Accellion campaign by name recognition alone, argues for treating any vendor-issued precautionary advisory from this product category with above-average urgency, even absent a named CVE.
- Confirm any Kiteworks deployment in your environment is running version 9.5.1 or later, regardless of whether you participated in the shutdown window.
- Ask your file-transfer and content-collaboration vendors directly whether they have a defined process for acting on government-sourced threat warnings before exploitation is confirmed, and what your organization would be told and when.
- Review access logs on any Kiteworks or comparable file-transfer system for the period around September 25 to 27 for anomalous authentication or data-transfer activity, even without a confirmed incident.
- Treat this as a prompt to inventory all internet-facing file-transfer software in your environment; this product category has a disproportionate history as an attacker entry point.
Singapore telco Simba discloses a breach affecting more than 23,500 customers
HIGH · DATA BREACHWho: Simba, a Singapore mobile telecommunications operator
Customers affected: 23,549
Data exposed: names, identity card (NRIC) numbers, dates of birth, mobile phone numbers and email addresses tied to service registrations; Simba says no credit card or bank account information was at risk
Timeline: Simba discovered the breach on September 24, 2026, and stated it has since contained and resolved it; the exposure was first reported in security press on September 27
Regulator involvement: Singapore's Personal Data Protection Commission opened an investigation after becoming aware of the incident
Attack vector: not disclosed by the company as of publication
Response: Simba is notifying affected customers by email, a process it says will complete within one week, and says it found no evidence the exposed data has been maliciously misused
What happened
Simba, a Singapore mobile network operator, disclosed that a data breach discovered on September 24, 2026 exposed personal information belonging to 23,549 customers, including names, NRIC numbers, dates of birth, mobile phone numbers and email addresses tied to service registrations. The company said no credit card or bank account information was at risk and that it has since contained and resolved the breach, though it has not disclosed the attack vector or method of unauthorized access.
Singapore's Personal Data Protection Commission opened an investigation after becoming aware of the incident. Simba is notifying affected customers directly by email, a process the company says will be complete within one week, and reports finding no evidence to date that the exposed data has been maliciously misused. The disclosure follows an earlier incident affecting Singapore telecommunications companies, including Simba, tied to a Chinese state-linked espionage group in February 2026; the company and reporting to date have not established whether this newer breach is connected to that campaign.
Evidence
Verified against independently fetched sources:
1. DataBreaches.net, "Personal information of over 23,500 Simba customers leaked in data breach," September 27, 2026
2. Malay Mail, "Data breach affects 23,549 customers of Singapore telco Simba, personal data protection commission investigating"
What this means for your team
NRIC numbers and dates of birth are close to ideal inputs for identity-theft and account-takeover attempts against Singapore residents specifically, since NRIC functions similarly to a national identifier across banking, government and telecom services there. If you operate in Singapore or serve Singapore customers, this breach is a useful trigger to review whether your own fraud-detection controls treat a leaked NRIC-and-date-of-birth pair as a credential-stuffing and identity-fraud risk, not just a privacy incident for the breached company alone.
An undisclosed attack vector, three days after discovery, is itself worth tracking; when the vector eventually becomes public, it is worth a quick check against your own telecom or customer-registration systems for the same exposure pattern.
- If you hold customer data for Singapore residents, review whether your fraud and account-takeover monitoring accounts for NRIC and date-of-birth exposure as a distinct risk signal, not a generic PII incident.
- If you are a Simba customer, or work with an organization that is, watch for the company's direct email notification, expected within a week of disclosure, and verify its authenticity before clicking any links, given the elevated phishing risk that follows telecom breaches.
- Track this disclosure for an eventual attack-vector update from Simba or the Personal Data Protection Commission, and check your own environment for the same exposure pattern once it is known.
- If you operate telecom or similar registration systems in the APAC region, confirm your incident-notification timeline and regulator-engagement process would meet a comparable standard if you were in Simba's position today.
Also notable
Items that scored well on our ranking but sat below the threshold for full treatment today. Each is sourced; none has been verified to the two-source standard we apply above.
- Cryptocurrency exchange Bitget raised its loss estimate from the September 24 hack, attributed by its CEO to North Korea, to $387.5 million after additional on-chain tracing identified Zcash and TRON assets omitted from the original accounting. The exchange launched a Recovery Bounty Program offering a 5 percent reward on stolen funds voluntarily frozen or recovered. SecurityWeek
- The federal patching deadline hit today, September 27, for two flaws CISA added to its Known Exploited Vulnerabilities catalog earlier this week: CVE-2026-5430, a critical WSO2 path-traversal flaw enabling remote code execution that watchTowr says has seen exploitation attempts since at least September 13, and CVE-2026-71362, an Adobe Commerce and Magento authorization flaw that lets an attacker switch a customer session to another account. The Hacker News
FAQ
What are CVE-2026-88771 and CVE-2026-88772, and were they exploited before a patch existed?
They are two critical, CVSS 9.5 vulnerabilities in Citrix NetScaler ADC and Gateway. CVE-2026-88771 is an improper input validation flaw allowing unauthenticated remote code execution; CVE-2026-88772 is a memory overflow affecting appliances with DTLS enabled. Citrix confirmed on September 27, 2026 that both were exploited in the wild before patches were publicly available, following disclosure by security firm watchTowr on September 26.
Does patching the NetScaler flaws remove the risk?
Not on its own, according to Citrix. The company explicitly warned that updating alone does not remove the risk of prior compromise on any appliance that was internet-exposed and unpatched, and recommended credential resets, certificate revocation and forensic investigation in addition to installing the patch.
What did CISA add to its Known Exploited Vulnerabilities catalog on September 27?
CISA added CVE-2026-65660, a Microsoft SharePoint code-injection flaw with confirmed active exploitation, and CVE-2026-67279, a MikroTik RouterOS flaw that, chained with CVE-2026-86060, allows full unauthenticated administrative takeover of vulnerable routers. Federal civilian agencies face a patching deadline of September 28, 2026 for both.
Why did Kiteworks tell customers to shut down their servers?
Kiteworks said it received credible threat intelligence from federal intelligence authorities indicating a threat actor might target some customer systems, and recommended a precautionary shutdown window, roughly six to nine hours depending on region and report, over the weekend of September 26 to 27, 2026. The company confirmed no customer compromise as of publication and said the measure was preventative.
What happened in the Simba data breach, and is my data at risk if I am not a Simba customer?
Simba, a Singapore telecom operator, disclosed a breach discovered September 24, 2026 affecting 23,549 customers, exposing names, NRIC numbers, dates of birth, mobile numbers and email addresses. No credit card or bank data was involved. The breach affects Simba's own customer base; if you are not a Simba customer your data was not part of this specific disclosure.
Is the Bitget crypto exchange hack connected to today's other stories?
No. It is included in Also Notable because its loss estimate was revised upward to $387.5 million and a recovery bounty program launched, both developments continuing from the original September 24, 2026 incident, which Bitget's CEO has attributed to North Korea.
Related reading from the community: past editions and analysis in the Breach Intelligence briefing archive, practitioner material on building a vulnerability management program around exploited flaws, guidance on third-party and vendor-risk frameworks, and the wider library of frameworks and checklists on CISO Platform.

Comments