VYPR
AI Brief2026-09-30· generated Sep 30, 2026

What you need to know today.

Citrix NetScaler zero-days actively exploited; GitLab flaw draws probes; multiple critical Netcore vulnerabilities disclosed.

Citrix NetScaler ADC and Gateway are facing a barrage of exploitation following the disclosure of two critical zero-day vulnerabilities. CVE-2026-88771, a pre-authentication command injection flaw, and CVE-2026-88773, an HTTP request smuggling vulnerability, have been actively exploited in the wild for weeks, impacting government, banking, and professional services sectors. The exploitation is believed to be widespread, with custom malware identified in some attacks. Additionally, CVE-2026-88775, a memory overflow vulnerability, is also present in affected versions. These vulnerabilities allow unauthenticated attackers to achieve remote code execution and other malicious actions. Citrix has released patches, and organizations are urged to update immediately. As reported by CyberScoop, these zero-days were exploited before Citrix issued warnings, leading to significant disruption. CISA has added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog.

GitLab has become the target of widespread exploitation for a critical vulnerability, CVE-2026-87719, which allows authenticated users to read arbitrary files under certain conditions. This flaw affects multiple versions of GitLab EE, with patches released for versions 18.3 through 19.3. The vulnerability has been observed in the wild, with scanners actively probing for instances of the flaw shortly after its disclosure, as noted by CyberScoop. The CVSS score of 9.9 highlights the severity of this file-read vulnerability, which could potentially expose sensitive information within GitLab instances. Rapid7 and GovInfoSecurity have also reported on the active exploitation and the potential impact of this vulnerability.

A cluster of critical vulnerabilities has been disclosed in Netcore NR289-GE devices, with CVE-2026-101077, CVE-2026-101076, and CVE-2026-101075 being particularly concerning. These flaws, affecting version 1.4.5102, include missing authentication in the process_request function, OS command injection via the ntp_ip argument in /set_ntp_server_ip.cgi, and OS command injection via the mac argument in /location_time.cgi. These vulnerabilities allow for remote exploitation without authentication, posing a significant risk to users of these devices. As detailed by Vypr Intelligence, these issues could enable attackers to gain control over affected devices.

Multiple critical vulnerabilities have been identified in IBM Concert versions 1.0.0 through 3.0.0. These include CVE-2026-6928 (use-after-free), CVE-2026-6730 (buffer overflow), and CVE-2026-6721 (arbitrary command execution). The use-after-free vulnerability can lead to memory corruption or arbitrary code execution, while the buffer overflow allows local users to execute arbitrary code. Furthermore, an unauthenticated remote attacker can exploit CVE-2026-6721 by supplying specially crafted input to achieve command execution on the underlying system. Vypr Intelligence has documented these 15 disclosed vulnerabilities, emphasizing the critical nature of the code execution flaws.

Critical vulnerabilities have been disclosed in Senxitoyshuyi UI's Netcore NR289-GE 1.4.5102. Specifically, CVE-2026-101077 involves missing authentication in the process_request function of the boa_temp Handler, allowing remote attacks. CVE-2026-101076 enables OS command injection through manipulation of the ntp_ip argument in the system function of the CGI Handler component. Additionally, CVE-2026-101075 allows OS command injection by manipulating the mac argument in the system function of the Location Time Handler. These vulnerabilities collectively present a severe risk, enabling unauthenticated remote attackers to compromise affected devices, as reported by Vypr Intelligence.

A critical template injection vulnerability, CVE-2026-97359, has been discovered in HFS2 versions 2.4.0 and earlier. This flaw resides within the multipart upload handler and allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax within a filename. The exploitability of this vulnerability is high, as it requires no authentication and can be triggered remotely. This disclosure adds to a busy day for security teams, particularly those managing web-facing applications. The Hacker News briefly mentioned this alongside other significant security events.

Synthesized by Vypr AI
Citrix NetScaler Zero-Days Exploited; GitLab Probes Surge · VYPR