Citrix disclosed CVE-2026-88771 and CVE-2026-88772, both scoring 9.5 on the CVSS scale, affecting default configurations of its NetScaler ADC and Gateway products. Citrix confirmed exploits against unmitigated deployments and urged customers to patch immediately, though public warnings of attacks had circulated online since September 25, days before the formal disclosure.
darkreading.com
· 2026-09-29
Citrix administrators report being privately contacted by IT suppliers, law enforcement, and cybersecurity agencies warning of two unpatched NetScaler remote code execution vulnerabilities being exploited in the wild. Security firm watchTowr confirmed the flaws are distinct from CVE-2026-19490 and CVE-2026-19489 disclosed in August, and said patches are expected next week.
bleepingcomputer.com
· 2026-09-27
Google released security updates fixing 230 vulnerabilities, including a Chrome zero-day flaw that attackers are already exploiting in the wild. This marks the seventh Chrome zero-day patched by Google since the beginning of the year.
bleepingcomputer.com
· 2026-09-09
Microsoft's September security update addressed 974 unique CVEs, the largest Patch Tuesday release yet, including two zero-day flaws already being actively exploited. Windows accounted for the vast majority of fixes at 723, with Office, SQL, SharePoint and Azure making up the rest, while 13 issues were rated Critical.
darkreading.com
· 2026-09-08