Weekly Cyber Briefing 02.10.2026
Weekly Cyber Update: 2 October 2026
This week, we look at only two stories, related to the impact of zero-day vulnerabilities at Citrix and Kiteworks
Weekly Cyber Briefing 02.10.2026
This week, we look at only two stories, related to the impact of zero-day vulnerabilities at Citrix and Kiteworks
Most of this week has been about exploits of two critical zero-day flaws in Citrix NetScaler appliances. It makes a nice change to have vulnerabilities on the perimeter and not need to mention AI.
Citrix released fixes on 27 September for eight NetScaler ADC and Gateway vulnerabilities. Citrix confirmed that two of them, CVE-2026-88771 and CVE-2026-88772, had been exploited on unmitigated deployments.
The attacks started well before that. Mandiant found the earliest known exploitation of CVE-2026-88772 was on 3 September. GreyNoise has seen CVE-2026-88771 exploited since at least 24 September, and researchers believe that campaign also began earlier.
Mandiant says organisations in North America and Europe across government, financial services, education, telecoms, legal and professional services were likely compromised by the time the attacks were confirmed. It is aware of dozens of affected organisations and attributes the activity to advanced, suspected state-sponsored actors. No victims have been named publicly.
The second wave is now under way. One threat intelligence firm recorded live exploitation attempts within minutes of watchTowr releasing a proof-of-concept exploit for CVE-2026-88771. Mandiant expects broad, opportunistic exploitation by a range of threat actors in the near term.
A number of Assured clients proactively shut down their Citrix appliances after becoming aware of the issue until they could patch. This requires a firm understanding of the implications and a well-practised response plan to make sure it can happen quickly.
CVE-2026-88771 lets an unauthenticated attacker execute arbitrary commands because of improper input validation. It affects all NetScaler deployments, including those in default configuration. CVE-2026-88772 is a memory overflow in DTLS, which is enabled by default on VPN virtual servers.
Once inside, attackers used custom web shells and tunnelling malware to gain root access and steal credentials. Mandiant tracks the malware as WHIPSHOT and SLAPSHOT. On some victims, they moved laterally into internal networks.
Citrix recommends upgrading to these builds:
Secure Private Access hybrid deployments using NetScaler instances also need upgrading. Google warns that the interim mitigations only cover CVE-2026-88772, not CVE-2026-88771.
Secure file transfer provider Kiteworks asked customers to take production systems offline for a weekend after federal authorities warned of an imminent attack. It might not have been huge news, but the proactive shutdown nature of this incident made it interesting.
On 25 September, Kiteworks emailed customers citing credible intelligence from law enforcement. It told self-managed customers on premises, AWS or Azure to take their own systems offline, and it shut down the systems it hosts.
On 28 September, it told customers they could resume normal operations, saying its monitoring had shown no abnormal activity.
Very little has been made public. At the time of the warning there was no public CVE, patch, exploit description or named threat group. Kiteworks has declined to say which federal authority provided the intelligence.
During the shutdown, Kiteworks found a previously unknown critical flaw in Advanced Forms. The tool is used by fewer than 1% of customers, around 50 organisations, and the company says its other products were unaffected. Kiteworks says it deployed a fix during the window and has no indication the flaw was exploited. It recommends release 9.5.1.
The history explains the caution and points to decisive incident response. Kiteworks was formerly Accellion, and rebranded in 2021 after an extortion gang used a flaw in its legacy file transfer appliance to breach hundreds of organisations. File transfer platforms concentrate sensitive data from many organisations in one place, which makes them prime targets for mass data theft.