If you just remember one thing from this briefing…
A Citrix NetScaler zero-day sat open to attackers for three weeks before anyone called it a vulnerability.
CVE-2026-88771 and CVE-2026-88772 were exploited from 3 September, planting webshells on NetScaler ADC and
Gateway appliances; Citrix disclosed and patched only on 27 September. If NetScaler sits in your estate,
assume compromise, not just exposure, and hunt for webshells before trusting the patch. Ask your team when
detection on edge appliances was last tested, not just patching.
Priority3–27 Sep
Citrix NetScaler zero-days exploited for three weeks before disclosure
Citrix confirmed CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, in NetScaler ADC and Gateway on 27
September, after researchers traced exploitation to 3 September. Attackers used the flaws to drop
webshells on default configurations, reaching VPN, ICA proxy and RDP proxy services weeks before any
patch existed.
So what: patching alone will not remove an existing webshell. Treat any
internet-facing NetScaler unit as a forensic question, not just a patch ticket.
Priority25–30 Sep
Three more products join the exploited-vulnerability catalogue in five days
CISA added SharePoint flaw CVE-2026-65660 and Mikrotik RouterOS flaw CVE-2026-67279 on 25 September,
then Cisco Catalyst SD-WAN Manager auth-bypass CVE-2026-76504 (CVSS 9.8) on 30 September — already past
its 3 October deadline. Each gives an attacker admin-level control once exposed.
So what: SD-WAN orchestration controls every connected site at once. Confirm
Catalyst SD-WAN Manager is patched or isolated today, not scheduled.
Watch18–30 Sep
South African ANSP finds ransomware-linked malware in its weather OT network
ATNS, which manages roughly 10% of global airspace, found malware consistent with early-stage ransomware
in operational technology supplying weather data for air navigation at Gqeberha, with signs of
exfiltration to China-based IP addresses. It has not ruled out insider involvement; no flight disruption
has been reported.
So what: weather-feed OT beside safety systems is a realistic target. Confirm
your own OT segmentation from general IT — do not assume it.
Watch2 Oct
Qilin lists Thai Lion Air on its leak site
Qilin, the group behind this year's Tulsa International Airport and Malaysia Airlines claims, added
Thai Lion Air to its leak site on 2 October, threatening to publish data unless negotiations begin. No
data sample is yet public and the claim is unverified beyond the listing.
So what: three airline and airport claims from one group this year make the
sector a standing target, not a one-off.