TL;DR
Two critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are actively exploited in attacks; patches released. Oracle PeopleSoft CVE-2026-35273 exploitation surges via WAF bypass tricks. Cloudflare patches container isolation flaw exposing multi-tenant data.
Executive Summary
- Citrix confirmed two NetScaler RCE zero-days under active exploitation; security updates released September 27, with federal remediation deadline September 30.
- ShinyHunters extortion gang escalates Oracle PeopleSoft campaign using URL-encoding bypass to evade web application firewall mitigations, resuming mass exploitation.
- Cloudflare patched a cross-tenant isolation flaw in Containers and Sandboxes allowing paid customers to recover residual data from other customers’ containers.
- Lunex malware-as-a-service platform abuses AMD kernel drivers to disable endpoint security while stealing browser credentials via compromised Ukrainian websites.
Top Threats Today
1. Citrix NetScaler RCE Zero-Days Actively Exploited
Severity: CRITICAL Affected: Technology Government
Citrix has confirmed two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway are being actively exploited in the wild [1][2]. CVE-2026-88771 involves improper input validation allowing unauthenticated attackers to execute arbitrary commands [4], while CVE-2026-88772 is a buffer overrun flaw enabling RCE or denial of service [3]. One of the flaws affects every deployment on an affected version [1]. Citrix released security updates on September 27, 2026 ⚠[1][2], with CISA setting a federal remediation deadline of September 30, 2026 [3][4].
Sources:[1] The Hacker News[2] BleepingComputer[3] CISA KEV[4] CISA KEV
Recommended Action
- Immediately apply Citrix security patches to all NetScaler ADC and Gateway instances; prioritize this as a network-critical update ahead of the September 30 federal deadline
- If patches cannot be deployed immediately, isolate affected NetScaler instances or restrict inbound access to trusted networks only
- Monitor NetScaler logs for exploitation indicators including unexpected command execution or authentication bypass attempts
- Verify patch deployment across all NetScaler deployments in your estate before September 30
2. ShinyHunters Resumes Oracle PeopleSoft Mass Exploitation via WAF Bypass
Severity: HIGH Affected: Technology
Google has warned of renewed mass exploitation of CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft, involving the ShinyHunters-linked extortion gang [1]. The threat actors are using URL-encoding bypass tricks to evade web application firewall (WAF) rules designed to mitigate the vulnerability, allowing widespread exploitation to resume on unpatched servers [2]. The critical flaw could result in remote code execution and web shell deployment across multiple sectors globally [1].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Patch Oracle PeopleSoft to the latest available version to close CVE-2026-35273; if patching is delayed, apply WAF rules and monitor for URL-encoded payloads in addition to standard filtering
- Review PeopleSoft logs for successful exploitation attempts, particularly looking for unusual command execution or file creation post-authentication
- If breach is suspected, assume credential theft and web shell persistence; conduct forensic analysis for backdoors
- Increase monitoring of PeopleSoft environments for reconnaissance activity and lateral movement
3. Cloudflare Container Cross-Tenant Data Exposure Patched
Severity: HIGH Affected: Technology
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers running on the same physical host [1]. The flaw represented a multi-tenant isolation bypass, exposing ephemeral data and potentially sensitive computation artifacts to lateral enumeration.
Sources:[1] BleepingComputer
Recommended Action
- Verify that your Cloudflare Workers Paid account has received the container isolation patch; check your account settings for confirmation
- If you use Cloudflare Containers for sensitive workloads, audit your container logs for any indicators of unauthorized data access during the vulnerability window
- Review any secrets, credentials, or sensitive data that may have been processed in containers during the vulnerability period
4. Lunex Malware Platform Abuses AMD Drivers; ClickFix Distribution Observed
Severity: HIGH Affected: Technology
The Psychedelic Stealer malware, distributed via compromised Ukrainian websites using ClickFix-style fake Cloudflare verification checks, is part of a wider malware-as-a-service ⚠ (MaaS) platform called Lunex [1]. Lunex abuses AMD kernel drivers to disable endpoint security monitoring and steal browser credentials [1]. The attack chain involves four stages and targets users via social engineering on legitimate-appearing verification pages.
Sources:[1] The Hacker News
Recommended Action
- Update endpoint detection and response (EDR) tools to detect AMD driver exploitation and unsigned kernel module loading attempts
- Educate users to verify domain URLs carefully before clicking on verification pages; legitimate platforms do not require re-verification via pop-up checks
- Monitor for suspicious AMD driver-related process execution and disable unnecessary AMD driver services where possible
- Isolate infected systems and reset browser credentials, particularly targeting authentication tokens for financial and email accounts
Today’s Action Checklist
- ☐ URGENT: Apply Citrix NetScaler patches to all ADC and Gateway instances before September 30 deadline
- ☐ URGENT: Patch Oracle PeopleSoft CVE-2026-35273; implement enhanced WAF rules for URL-encoded payload detection if patching is delayed
- ☐ HIGH: Verify Cloudflare Containers patch deployment if using Workers Paid tier
- ☐ HIGH: Update EDR and antimalware signatures to detect Lunex/Psychedelic Stealer and AMD driver abuse
- ☐ HIGH: Scan logs for exploitation of Citrix NetScaler, Oracle PeopleSoft, and suspicious AMD driver activity