DKDKCISSPSearch
AI SecurityDEVELOPING

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories.

DKCISSP News DeskThe Hacker News28 Sept 2026, 7:30 pm
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

Citrix released patches for vulnerabilities numbered CVE-2026-88771 through CVE-2026-88778 on Sunday, and confirmed that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” CVE-2026-88771 stems from improper input validation and allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices running a default configuration.

The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities: The NCSC recommends following vendor best practice advice to mitigate vulnerabilities.

CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service.

Hackers exploit Gyazo server flaw to steal 23.6 million user records Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing about 23.62 million user records and metadata tied to hundreds of millions of images.

The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.

Cybersecurity and Infrastructure Security Agency (CISA), on September 25, 2026, added CVE-2026-87902, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 28, 2026.

What happened

Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.

What changed

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

Who is affected

Citrix released patches for vulnerabilities numbered CVE-2026-88771 through CVE-2026-88778 on Sunday, and confirmed that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” CVE-2026-88771 stems from improper input validation and allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices running a default configuration.

The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities: The NCSC recommends following vendor best practice advice to mitigate vulnerabilities.

Why it matters

CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service.

Hackers exploit Gyazo server flaw to steal 23.6 million user records Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing about 23.62 million user records and metadata tied to hundreds of millions of images.

Technical details

The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.

Cybersecurity and Infrastructure Security Agency (CISA), on September 25, 2026, added CVE-2026-87902, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 28, 2026.

CISA said "threat actors are actively exploiting these vulnerabilities globally," urging federal agencies to apply patches by Wednesday.

Response

While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers.

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

What security teams should do

Citrix acknowledged that, since threat actors change techniques, tactics, and procedures and infrastructure frequently, the indicators of compromise they used “might fail to identify actual compromises,” so customers should “retain the services of experienced forensic investigators to assess [their] environment.” The US Cybersecurity and Infrastructure Security Agency (CISA) added the two actively exploited flaws to its Known Exploited Vulnerabilities catalog on Sunday and ordered US federal civilian agencies to address them by Wednesday (September 30, 2026) and perform forensic triage to check for evidence of compromise.

The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.

Attribution

The Hacker News: A domain used as harmless placeholder text showed up in roughly 1,700 repositories.

NCSC-UK: The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Help Net Security: Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.

The Hacker News: Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am