DKDKCISSPSearch
Threat ResearchDEVELOPING

Week in review: FortiBleed is still active, Patch Tuesday forecast - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare fintech vendor In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles.

DKCISSP News DeskHelp Net Security11 Oct 2026, 1:30 pm
Week in review: FortiBleed is still active, Patch Tuesday forecast - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it.

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.

Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution.

While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.

Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

FortiBleed is still active, with attackers locking admins out of Fortinet firewalls Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S.

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

While Citrix has not found evidence that attackers have begun exploiting CVE-2026-107406 in the wild, the company warned of several other NetScaler vulnerabilities that attackers have abused since the start of the year.

What happened

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255) SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.” Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it.

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.

What changed

Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution.

While SonicWall has not yet flagged this vulnerability as actively exploited in its Tuesday advisory, Previdian founder and security researcher Ryan Dewhurst told BleepingComputer on Friday that the company's honeypot network has detected exploitation attempts consistent with the CVE-2026-102255 flaw.

Who is affected

Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

FortiBleed is still active, with attackers locking admins out of Fortinet firewalls Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S.

Why it matters

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

Technical details

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

While Citrix has not found evidence that attackers have begun exploiting CVE-2026-107406 in the wild, the company warned of several other NetScaler vulnerabilities that attackers have abused since the start of the year.

October 2026 Patch Tuesday forecast: Time for an Office cleanup September 2026 Patch Tuesday set an all-time record with 973 CVEs addressed across the Microsoft portfolio.

Response

Reuters reports that Jordanian authorities detained Saif al-Din Khader, alias Rey, last week, with two of its three sources placing the arrest on Tuesday.

If teams can’t patch before the weekend, isolate the Appliance Work Place interface from public internet access.

What security teams should do

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare fintech vendor In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles.

Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.

What remains unknown

In its advisory on Tuesday, SonicWall did not say if the bug was actively exploited, but security researchers at Previdian said that the company’s honeypots had detected exploitation.

Dewhurst also added that while this activity is consistent with active exploitation attempts, Previdian has not yet established "whether those attempts would have successfully compromised any systems." While Internet threat watchdog Shadowserver now tracks more than 400 SMA1000 appliances exposed online, there is no information on how many are honeypots or have already been patched against CVE-2026-102255 attacks.

Attribution

Help Net Security: Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare fintech vendor In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles.

SC Media: Attackers are now exploiting a CVSS 10.0 server-side request forgery (SSRF) flaw in SonicWall’s SMA1000 Appliance Work Place.

BleepingComputer: Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.

BleepingComputer: Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN THREAT RESEARCH

More cybersecurity reporting

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery PhrasesThe Hacker News · 16 Oct 2026, 5:30 amUAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTMLThe Hacker News · 8 Oct 2026, 8:56 pmMicrosoft Teams to get support for third-party deepfake detection toolsBleepingComputer · 8 Oct 2026, 5:38 pmMicrosoft Outlook to block MSIX attachments starting NovemberBleepingComputer · 7 Oct 2026, 9:14 pm