Lead · Vulnerabilities
The edge gave way in three places and only two of them made the catalogue
CISA added Apple's CoreGraphics flaw and a Cisco SD-WAN Manager zero-day to KEV, while the NetScaler pair that attackers are already using for root access sits outside it.
CISA's catalogue took two new entries. CVE-2026-86950 is an out-of-bounds write in CoreGraphics across iOS, macOS and iPadOS that may lead to arbitrary code execution, and which Apple says was used in extremely sophisticated targeted attacks on iOS devices. CVE-2026-76504 is a hex-encoding flaw in Cisco Catalyst SD-WAN Manager that lets an unauthenticated remote attacker reach the box with the privileges of the admin user, because of improper handling of URI encoding in an HTTP request; Cisco published its advisory on 30 September and confirmed attackers are exploiting it.
The thing not in the catalogue is the thing doing the most damage. Citrix NetScaler ADC and Gateway carry CVE-2026-88772, a memory flaw rated CVSS 9.5 with a pre-auth path to shellcode execution, and CVE-2026-88771, improper input validation allowing unauthenticated command execution. Mandiant and Google Threat Intelligence Group saw exploitation in September against organisations in North America and Europe, with web shells, tunnelling malware, root access, credential theft and lateral movement, and implants named WHIPSHOT and SLAPSHOT; several firms have confirmed weeks-long attacks on government and financial targets. The flaws affect default configurations, which is the industry's polite way of saying everybody.
Read the week's other confession alongside it. In France, an attacker used stolen staff passwords at the tax administration to take data on hundreds of thousands of taxpayers and businesses across June and July, and neither the tax administration nor the national cybersecurity agency saw it leave for seven weeks. The attack was not sophisticated, the agency said. That sentence is rarer and more useful than any CVSS score printed today.
Why it mattersIf you run NetScaler, SD-WAN Manager or managed Apple fleets, today is a patch-and-hunt day, and the NetScaler boxes need credential rotation and web shell hunting, not just a version bump.
- 1CISA KEVCVE-2026-86950 Apple Multiple Products: Apple Multi…
- 2Security newsApple Zero-Day Vulnerability Weaponized in Targeted…
- 3RSSApple patches CoreGraphics zero-day flaw exploited…
- 4CISA KEVCVE-2026-76504 Cisco Catalyst SD-WAN Manager: Cisco…
- 5Security newsCisco warns of new SD-WAN zero-day exploited in att…
- 6RSSCisco warns of new SD-WAN zero-day exploited in att…