Lead · Vulnerabilities
Citrix, Cisco, FortiMail and Zimbra are all being exploited, and the CVE feed has gone quiet
Four internet-facing products under live attack in the same week, two fresh KEV entries, and no NVD enrichment since Tuesday afternoon.
Start with Citrix. CVE-2026-88772 (CVSS 9.5) is a memory flaw in NetScaler ADC and Gateway that researchers have now described as a pre-authentication path to shellcode execution, and it is not theoretical: Mandiant Consulting and Google Threat Intelligence Group watched threat actors use it against organisations in North America and Europe in September and drop malware tracked as WHIPSHOT and SLAPSHOT. Several firms have confirmed exploitation of both CVE-2026-88771 and CVE-2026-88772 against government and financial organisations over a period of weeks. LevelBlue's THOR team describe the post-exploitation work in the kind of detail that ruins a morning: a superuser account created, and a web shell mapped to URLs shaped like stylesheets. One operator was on a NetScaler Gateway on 24 September from 149.104.78.141, three days before public disclosure, which is the usual order of events and not a surprise to anyone who has been awake since 2017.
Then the rest of the row. Cisco's Catalyst SD-WAN Manager has CVE-2026-76504, a critical authentication bypass with a CVSS of 9.8 that lets a remote attacker with no login reach admin privileges; Cisco published on 30 September, attackers were already there, and CISA added it to the Known Exploited Vulnerabilities catalogue. Fortinet is warning that CVE-2026-104286 in FortiMail, a path traversal plus NULL-byte neutralisation failure allowing an unauthenticated attacker to write arbitrary files, is being exploited in zero-day attacks; it went into KEV on 1 October. And Microsoft's researchers report CVE-2026-73570 in Zimbra Collaboration Suite, an unauthenticated OS command injection in the SNMP notification path, scored 8.9, exploited before disclosure, used to drop web shells and reach mailbox data, and under certain conditions reachable by a crafted email with no user interaction at all.
The through-line is not sophistication. It is that all four of these are the box in front of the thing: the gateway, the manager, the mail security appliance, the collaboration server. The boxes you bought so that the rest of it would be fine. Meanwhile, in our collection window, the National Vulnerability Database — the single largest source we ingest — has published nothing since 30 September at 15:15, which means the three highest-priority flaws of the week carry no NVD-sourced CVSS, CWE or CPE enrichment in this dataset during the exact days you needed it for your SBOM correlation. Maureen notes that 'we were waiting on the authoritative source' is not a control, and that your regulator will ask what you did on the Thursday.
Why it mattersIf you run NetScaler, Catalyst SD-WAN Manager, FortiMail or Zimbra, patch and then hunt for superusers, web shells on odd-looking paths and SNMP-adjacent command execution, because patching stops the next intrusion, not the one from last week.
- 1Security newsCitrix NetScaler CVE-2026-88772 Exploit Details Sho…
- 2Security newsGovernment, Finance Orgs Targeted in Weeks-Long Net…
- 3Security newsAttackers Exploit NetScaler Flaw for Root Access, D…
- 4Security newsCitrix NetScaler Post-Exploitation Payload Creates…
- 5AlienVault OTXCitrix NetScaler CVE-2026-88771: Observed Exploitat…
- 6AlienVault OTXSwarming Against Citrix 0-Day Exploitation — A mali…