TL;DR
Rejetto HFS vulnerability (CVE-2026-61500) is actively scanned for exploitation allowing RCE. Microsoft Exchange flaw (CVE-2026-96940, CVSS 8.8) enables authenticated privilege escalation. Dell System Update tool contains multiple flaws enabling root access. Additionally, Denmark's CPR registry breach exposed 8.8 million people's personal data.
Executive Summary
- Rejetto HFS vulnerability (CVE-2026-61500) is under active scanning with demonstrated RCE and account takeover capability.
- Microsoft Exchange Server flaw (CVE-2026-96940, CVSS 8.8) allows authenticated attackers to escalate privileges and read other users' mailboxes; out-of-band patches issued.
- Dell System Update CLI tool contains eight critical vulnerabilities enabling root privilege escalation; multiple CVE identifiers disclosed.
- Denmark's Central Population Register (CPR) suffered a breach exposing approximately 8.8 million registered individuals' personal information.
- Citrix NetScaler issue tracking continues with CVE-2026-88779 added to CISA's Known Exploited Vulnerabilities catalog.
Top Threats Today
1. Rejetto HFS Remote Code Execution Under Active Scanning
Severity: HIGH Affected: Technology
Hackers are actively scanning for Rejetto HFS vulnerability CVE-2026-61500, which allows session forgery, account takeover, and remote code execution [1]. The vulnerability involves weak signing key mechanisms that permit attackers to recover the session-cookie signing key and gain administrative access [2]. Active scanning indicates imminent exploitation risk across internet-facing Rejetto HFS deployments.
Sources:[1] BleepingComputer[2] SecurityWeek
Recommended Action
- Identify and inventory all Rejetto HFS instances in your environment immediately.
- Apply available security patches from Rejetto without delay.
- Restrict network access to HFS administrative interfaces using firewall rules or VPN.
- Monitor logs for suspicious session-cookie activity and failed authentication attempts.
2. Microsoft Exchange Privilege Escalation Flaw
Severity: HIGH Affected: Technology
Microsoft has released out-of-band security updates addressing a high-severity vulnerability in Microsoft Exchange Server tracked as CVE-2026-96940, rated CVSS 8.8 [1]. The flaw features weak authorization checks that allow authenticated attackers to escalate privileges and access other users' mailboxes under certain conditions ⚠ [1]. Out-of-band patching indicates Microsoft deemed the threat significant enough to warrant an emergency release cycle outside normal Patch Tuesday scheduling.
Sources:[1] The Hacker News
Recommended Action
- Retrieve and apply Microsoft's out-of-band Exchange patches immediately.
- Review mailbox access logs for anomalous cross-user access patterns.
- Enforce multi-factor authentication (MFA) on all Exchange user accounts.
- Segment Exchange infrastructure from general network traffic where possible.
3. Dell System Update Tool Root Privilege Escalation
Severity: HIGH Affected: Technology
Dell has warned customers to patch critical vulnerabilities in the System Update (DSU) command-line interface deployment tool [1]. Eight CVE identifiers have been assigned to flaws in this tool: a reported vulnerability (identifier could not be verified against NVD and has been withdrawn), CVE-2026-63697, CVE-2026-71168, CVE-2026-86361, CVE-2026-86362, CVE-2026-63688, CVE-2026-63692, ⚠ and CVE-2021-21551 [1]. These flaws enable attackers to gain root privileges on affected systems, creating a critical risk for any organization using Dell DSU for system administration and deployment.
Sources:[1] BleepingComputer
Recommended Action
- Audit all systems where Dell System Update is deployed or scheduled for deployment.
- Apply Dell's latest security patches to the DSU tool immediately.
- Restrict DSU execution to authorized administrators using application whitelisting.
- Monitor DSU command execution logs for unauthorized privilege escalation attempts.
4. Denmark Population Registry Breach Exposes 8.8 Million Records
Severity: HIGH Affected: Government
Denmark's Central Population Register (CPR) has disclosed a data breach affecting approximately 8.8 million registered individuals [1]. The breach exposed personal information of nearly the entire Danish population registered in the CPR system. Details regarding the extent of exposed data elements and breach timeline remain limited at this time.
Sources:[1] BleepingComputer
Recommended Action
- Monitor official CPR and Danish Data Protection Authority communications for breach details and remediation guidance.
- If your organization operates in Denmark, prepare breach notification templates for affected individuals.
- Review your own population registry or PII storage systems for similar vulnerabilities.
- Consider credit monitoring or identity theft protection offers for affected populations.
5. Citrix NetScaler Memory Buffer Flaw Added to CISA KEV Catalog
Severity: HIGH Affected: Technology
CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-04 [1]. The vulnerability affects Citrix NetScaler ADC and Citrix NetScaler Gateway, involving improper restriction of operations within the bounds of a memory buffer that could allow denial of service [1]. Federal remediation is due by 2026-10-07 [1].
Sources:[1] CISA KEV
Recommended Action
- If operating Citrix NetScaler infrastructure, retrieve Citrix's latest security patches immediately.
- Verify all customer-managed NetScaler deployments are patched and current.
- Monitor NetScaler instances for signs of denial-of-service attack or memory exhaustion.
- Report patch status to your federal/government oversight bodies if applicable; CISA remediation deadline is 2026-10-07.
Today’s Action Checklist
- ☐ URGENT: Scan your environment for Rejetto HFS instances and apply security patches immediately.
- ☐ URGENT: Deploy Microsoft Exchange out-of-band patches and review mailbox access logs for unauthorized access.
- ☐ URGENT: Audit Dell System Update deployments and apply vendor security patches; restrict DSU tool access to authorized administrators.
- ☐ URGENT: Patch Citrix NetScaler instances to comply with CISA KEV remediation deadline of 2026-10-07.
- ☐ If your organization is affected by the Denmark CPR breach, prepare breach notification templates and monitor for identity theft indicators.