Security news.
Critical enterprise infrastructure is under heavy fire today as Citrix confirms two actively exploited NetScaler zero-day vulnerabilities, prompting emergency additions to CISA's Known Exploited Vulnerabilities catalog. Threat actors are also actively bypassing web application firewalls to deploy shells via an Oracle PeopleSoft flaw, while active exploitation of Microsoft SharePoint has escalated. Meanwhile, Cloudflare addressed a significant cross-tenant data exposure flaw in its container platform.
Citrix Confirms Two NetScaler RCE Zero-Days Exploited in Attacks
Citrix released emergency updates for two critical remote code execution vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway that are actively exploited in the wild, one affecting default configurations.
CISA Adds Actively Exploited Citrix NetScaler Flaws to KEV Catalog
CISA has added Citrix NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog following confirmed active adversary exploitation.
Microsoft SharePoint Code Injection Flaw CVE-2026-65660 Under Active Attack
CISA has mandated federal agencies patch a high-severity code injection vulnerability in Microsoft SharePoint after confirming active exploitation in the wild.
ShinyHunters Bypasses WAF Rules to Exploit Critical Oracle PeopleSoft Flaw
Threat actors are leveraging a URL-encoding trick to evade WAF mitigations for CVE-2026-35273 (CVSS 9.8), resuming mass exploitation of vulnerable Oracle PeopleSoft systems to deploy web shells.
Cloudflare Patches Containers Cross-Tenant Flaw Exposing Customer Data
Cloudflare fixed an isolation issue in Containers and Sandboxes that permitted paid Workers accounts to access residual data from co-located customer containers on the same physical host.
Kiteworks Advises Customers to Shut Down Servers Over Imminent Cyber Threat
Secure file-sharing vendor Kiteworks urged clients to take appliances offline for several hours following credible federal intelligence warning of imminent targeted attacks.
High-Severity Elementor CSRF Vulnerability Enables Full Site Takeover
A flaw carrying a CVSS score of 8.8 in the Elementor WordPress plugin allows unauthenticated attackers to hijack sites and create rogue administrator accounts if an authenticated admin clicks a malicious link.
GitHub Actions Re-Enabled While Still Containing Active Malware Payload
Two previously compromised third-party GitHub Actions were inadvertently restored by their maintainer, remaining active for over a week while still serving malicious payloads from the Mini Shai-Hulud campaign.