Security news.
Critical enterprise infrastructure is under heavy pressure today, led by active in-the-wild exploitation of unpatched Citrix NetScaler remote code execution flaws and Microsoft SharePoint injection vulnerabilities. Concurrently, threat actors are weaponizing WAF evasion techniques against Oracle PeopleSoft while emergency mitigation advisories roll out across enterprise file-sharing platforms. Security teams should prioritize patching edge appliances and validating web application firewall rules against encoding bypasses.
Citrix NetScaler Zero-Days Under Active Exploitation
Two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild, prompting some administrators to take systems offline ahead of vendor fixes.
CISA Adds Microsoft SharePoint Flaw to KEV Catalog
CISA has added CVE-2026-65660, a code injection vulnerability affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog following active exploitation against enterprise environments.
ShinyHunters Bypasses WAF Rules in Oracle PeopleSoft Exploits
Threat actors are using a URL-encoding bypass to evade web application firewall mitigations for CVE-2026-35273, resuming widespread exploitation to deploy web shells on vulnerable PeopleSoft servers.
Kiteworks Warns Customers to Take Systems Offline
Secure file-sharing provider Kiteworks urged clients to execute a temporary shutdown of server infrastructure following credible federal intelligence warning of an imminent cyberattack.
High-Severity CSRF Flaw Uncovered in Elementor WordPress Plugin
A cross-site request forgery vulnerability (CVSS 8.8) in the popular Elementor Website Builder plugin allows unauthenticated attackers to create rogue administrator accounts if an admin clicks a malicious link.
Lunex Stealer Abuses AMD Drivers to Evade Defenses
Part of a broader MaaS platform, the malware uses ClickFix-style lures and abuses legitimate AMD drivers to disable security monitoring and harvest browser credentials.
Compromised GitHub Actions Re-Enabled with Malicious Payloads
Two third-party GitHub Actions associated with the Mini Shai-Hulud campaign were mistakenly re-enabled and left active for over a week while still pointing to malicious code.
Salesforce Agentforce Flaws Allowed Zero-Click Data Exfiltration
Dubbed "SalesBleed," three vulnerabilities in Salesforce Agentforce enabled attackers to hijack autonomous agents, exfiltrate data, and orchestrate Slack-based phishing campaigns.