VYPR
AI Brief2026-09-29· generated Sep 28, 2026

What you need to know today.

Citrix NetScaler zero-days exploited, WordPress flaw actively attacked, and multiple critical vulnerabilities disclosed across networking and enterprise products.

Multiple critical vulnerabilities affecting Citrix NetScaler ADC and Gateway have been actively exploited in the wild, prompting warnings from CISA and NCSC. CVE-2026-88771, a critical improper input validation flaw, and CVE-2026-88772, a high-severity vulnerability, were added to the CISA Known Exploited Vulnerabilities (KEV) catalog. These zero-day flaws allow for remote code execution and have been exploited by attackers for weeks before patches were released. The vulnerabilities affect various versions of NetScaler ADC and Gateway, with patches available for versions prior to 14.1-73.37 and 13.1-64.23. Other related vulnerabilities, including CVE-2026-88773 (HTTP Request/Response smuggling) and CVE-2026-88775 (memory overflow), also impact these products. As The Register reported, these exploits highlight a recurring pattern of critical vulnerabilities in Citrix products.

A critical vulnerability in WordPress core, CVE-2026-87902, is being actively exploited. This flaw allows unauthenticated attackers to include arbitrary readable local PHP files outside the theme directory, potentially leading to remote code execution. Exploitation began within hours of the patch release, and it has also been added to the CISA KEV catalog. The vulnerability affects WordPress versions prior to 7.1.2, which has since been released to address the issue. Patchstack Blog noted that attackers started probing WordPress sites immediately after the patch became available.

A cluster of critical vulnerabilities has been disclosed across several Netcore router models, including the NBR200V2 and NBR100V2. CVE-2026-101001 and CVE-2026-101000, affecting the NBR200V2 and NBR100V2 respectively, allow for OS command injection through manipulation of arguments in their web management interfaces. Additionally, CVE-2026-101002, also impacting the NBR200V2, is an OS command injection flaw in its "Tools Ping Handler" component. These vulnerabilities, along with others like CVE-2026-101072 and CVE-2026-100896 affecting other Netcore and Totolink devices, highlight widespread command injection risks in consumer networking equipment. Vypr Intelligence reported on these Netcore vulnerabilities.

Critical vulnerabilities have been identified in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). CVE-2026-20192 and CVE-2026-20130, both with CVSS scores of 10.0, are present in these Cisco products. While details are scarce, the descriptions suggest a comprehensive internal security review uncovered these flaws. Separately, Oracle WebLogic Server is affected by CVE-2026-83021, a critical vulnerability in its Web Container component that allows for easy exploitation by unauthenticated attackers. These critical flaws in enterprise networking and middleware products underscore the need for prompt patching.

Several other critical vulnerabilities have been disclosed, including a path traversal flaw in Canonical LXD (CVE-2026-85526) that allows authenticated users to modify host files as root. Additionally, multiple stack-based buffer overflow vulnerabilities have been found in FAST devices (CVE-2026-101039, CVE-2026-101038, CVE-2026-101037), and an improper authentication vulnerability affects Seetong devices (CVE-2026-100886). These diverse vulnerabilities across different product types emphasize the broad range of threats organizations face.

Synthesized by Vypr AI
Citrix, WordPress Exploits Lead Daily Security Briefing · VYPR