This day 02:08 06:08 10:08 14:09 18:09 22:09
⚠ exploit status: CVE-2026-20079 · KEV
Info  2026-09-27 10:08Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-27 — Citrix NetScaler Zero-Days Exploited

Two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are under active exploitation in the wild, with no vendor patch yet available. Security firm watchTowr disclosed the vulnerabilities on September 26, and Citrix has not confirmed a remediation timeline. This is the most urgent item today: internet-exposed NetScaler appliances are at immediate risk of compromise while no fix exists.

Top items

Themes

Unpatched edge appliances under active attack. The Citrix NetScaler disclosure fits a broader pattern observed this month of threat actors targeting perimeter infrastructure before patches are available — consistent with the ongoing Cisco FMC exploitation (CVE-2026-20079KEV) and the Kiteworks shutdown advisory. Attackers continue to prioritise externally exposed appliances as high-value entry points.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db