search
CISA
Trends
- 1Citrix NetScaler flaws actively exploited, thousands exposed●🤖 Citrix NetScaler ADC/Gateway: CVE-2026-88771 + CVE-2026-88772 (unauth RCE) exploited in the wild. The first hits defau
Two unauthenticated remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in the wild against Citrix NetScaler ADC and Gateway appliances. The first affects default configurations, while the second requires DTLS, which is enabled by default on VPN virtual servers. Patches are available, the flaws have been added to CISA's Known Exploited Vulnerabilities catalog with a federal patching deadline of September 30, and Shadowserver reports over 23,000 exposed instances online.
- 2CISA adds two actively exploited Citrix NetScaler flaws to catalog▼⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affec
CISA has added CVE-2026-88771 and CVE-2026-88772, two vulnerabilities affecting Citrix NetScaler, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Both flaws are described as remote code execution vectors, meaning attackers can potentially run malicious code on affected appliances. Security teams are urged to check whether they run NetScaler and apply patches immediately, as exploited edge devices are a common entry point for intrusions.
- 3Check Point VPN flaw under active attack days after patch●Check Point confirms active attacks on CVE-2026-85102 began three days after patches dropped. CISA sets federal deadline
Check Point has confirmed that attackers began exploiting CVE-2026-85102, a vulnerability in its VPN products, just three days after patches were released. CISA has added the flaw to its exploited-vulnerabilities catalog and given federal agencies a September 25 deadline to apply the fix. Security teams are urged to patch immediately as exploitation continues.
- 4CISA Adds Two Actively Exploited Vulnerabilities to Catalog●🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad viso
The US Cybersecurity and Infrastructure Security Agency has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation in the wild. The listing requires federal civilian agencies to patch the flaws within mandated deadlines. Security teams are being urged to review the advisory and prioritize remediation of the affected software.
- 5Exploited WordPress vulnerability affects all versions since 4.7.0●🔴 EXPLOITED WordPress core CVE-2026-87902 is being exploited to run code on sites, and it affects every release back to
A WordPress core vulnerability tracked as CVE-2026-87902 is being actively exploited to run code on websites without requiring login. The flaw reportedly affects every release going back to version 4.7.0. CISA has added it to its catalog and is requiring federal agencies to patch by September 28. Administrators are being urged to update to WordPress 7.1.2 immediately.