Vulnerability News
Kanalga Telegramâda oâtish
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
Ko'proq ko'rsatish5 392
Obunachilar
+624 soatlar
+327 kun
+16130 kun
Ma'lumot yuklanmoqda...
O'xshash kanallar
Taglar buluti
Kirish va chiqish esdaliklari
---
---
---
---
---
---
Obunachilarni jalb qilish
Sentabr '26Sen '26
Sentabr '26
+197
0 kanalda
Avgust '26
+157
0 kanalda
Get PRO
Iyul '26
+185
0 kanalda
Get PRO
Iyun '26
+156
0 kanalda
Get PRO
May '26
+204
0 kanalda
Get PRO
Aprel '26
+187
0 kanalda
Get PRO
Mart '26
+254
0 kanalda
Get PRO
Fevral '26
+116
0 kanalda
Get PRO
Yanvar '26
+166
0 kanalda
Get PRO
Dekabr '25
+134
0 kanalda
Get PRO
Noyabr '25
+139
0 kanalda
Get PRO
Oktabr '25
+8
0 kanalda
Get PRO
Sentabr '25
+12
0 kanalda
Get PRO
Avgust '25
+13
0 kanalda
Get PRO
Iyul '25
+11
0 kanalda
Get PRO
Iyun '25
+12
0 kanalda
Get PRO
May '25
+18
1 kanalda
Get PRO
Aprel '25
+14
0 kanalda
Get PRO
Mart '25
+21
0 kanalda
Get PRO
Fevral '25
+17
0 kanalda
Get PRO
Yanvar '25
+15
1 kanalda
Get PRO
Dekabr '24
+262
1 kanalda
Get PRO
Noyabr '24
+206
1 kanalda
Get PRO
Oktabr '24
+166
0 kanalda
Get PRO
Sentabr '24
+146
0 kanalda
Get PRO
Avgust '24
+137
0 kanalda
Get PRO
Iyul '24
+96
1 kanalda
Get PRO
Iyun '24
+91
0 kanalda
Get PRO
May '24
+95
0 kanalda
Get PRO
Aprel '24
+104
0 kanalda
Get PRO
Mart '24
+149
0 kanalda
Get PRO
Fevral '24
+279
0 kanalda
Get PRO
Yanvar '24
+395
0 kanalda
Get PRO
Dekabr '23
+327
0 kanalda
Get PRO
Noyabr '23
+38
0 kanalda
Get PRO
Oktabr '23
+32
0 kanalda
Get PRO
Sentabr '23
+47
0 kanalda
Get PRO
Avgust '23
+53
0 kanalda
Get PRO
Iyul '23
+51
0 kanalda
Get PRO
Iyun '23
+42
0 kanalda
Get PRO
May '23
+43
0 kanalda
Get PRO
Aprel '23
+67
0 kanalda
Get PRO
Mart '23
+65
0 kanalda
Get PRO
Fevral '23
+45
0 kanalda
Get PRO
Yanvar '23
+67
0 kanalda
Get PRO
Dekabr '22
+62
0 kanalda
Get PRO
Noyabr '22
+71
0 kanalda
Get PRO
Oktabr '22
+70
0 kanalda
Get PRO
Sentabr '22
+55
0 kanalda
Get PRO
Avgust '22
+44
0 kanalda
Get PRO
Iyul '22
+54
0 kanalda
Get PRO
Iyun '22
+78
0 kanalda
Get PRO
May '22
+46
0 kanalda
Get PRO
Aprel '22
+77
0 kanalda
Get PRO
Mart '22
+105
0 kanalda
Get PRO
Fevral '22
+48
0 kanalda
Get PRO
Yanvar '22
+61
0 kanalda
Get PRO
Dekabr '21
+99
0 kanalda
Get PRO
Noyabr '21
+68
0 kanalda
Get PRO
Oktabr '21
+170
0 kanalda
Get PRO
Sentabr '21
+72
0 kanalda
Get PRO
Avgust '21
+104
0 kanalda
Get PRO
Iyul '21
+72
0 kanalda
Get PRO
Iyun '21
+292
0 kanalda
Get PRO
May '21
+1 344
0 kanalda
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 28 Sentabr | +8 | |||
| 27 Sentabr | +8 | |||
| 26 Sentabr | +6 | |||
| 25 Sentabr | +9 | |||
| 24 Sentabr | +7 | |||
| 23 Sentabr | +4 | |||
| 22 Sentabr | +6 | |||
| 21 Sentabr | +7 | |||
| 20 Sentabr | +3 | |||
| 19 Sentabr | +8 | |||
| 18 Sentabr | +7 | |||
| 17 Sentabr | +6 | |||
| 16 Sentabr | +8 | |||
| 15 Sentabr | +15 | |||
| 14 Sentabr | +6 | |||
| 13 Sentabr | +4 | |||
| 12 Sentabr | +6 | |||
| 11 Sentabr | +7 | |||
| 10 Sentabr | +12 | |||
| 09 Sentabr | +7 | |||
| 08 Sentabr | +6 | |||
| 07 Sentabr | +9 | |||
| 06 Sentabr | +7 | |||
| 05 Sentabr | +2 | |||
| 04 Sentabr | +5 | |||
| 03 Sentabr | +6 | |||
| 02 Sentabr | +11 | |||
| 01 Sentabr | +7 |
Kanal postlari
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration.
The bulletin came a day after security firm watchTowr
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
| 2 | Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CISA is amplifying Citrixâs disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778.Â
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.Â
Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrixâs advisories. If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in their recent publication, Security Bulletin for CVE-2026-88771 through CVE-2026-88778, to support organizations in assessing potential compromise. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility.Â
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
Steps to Take if NetScaler ADC is Suspected to be Compromised
Disclaimer
The information in this report is being provided âas isâ for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.
https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway | 115 |
| 3 | CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISAâs KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISAâs KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog | 71 |
| 4 | Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.
https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/ | 55 |
| 5 | Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-turns-claude-into-an-ai-marketplace-with-2-000-plus-plugins-and-connectors/ | 53 |
| 6 | Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/ | 59 |
| 7 | Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]
https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ | 66 |
| 8 | Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief
https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html | 118 |
| 9 | SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html | 113 |
| 10 | Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.
The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions
https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html | 95 |
| 11 | Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
https://thehackernews.com/2026/09/zero-trust-for-ai-agents-starts-with.html | 81 |
| 12 | Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day
https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html | 57 |
| 13 | Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.
The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.
"The attack chain begins with a fake CAPTCHA page and
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html | 50 |
| 14 | OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAIâs CEO said there is an âextensive and ongoing review related to our agentsâ use of internet access during training and evaluation.â
The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek.
https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/ | 46 |
| 15 | New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.
https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/ | 46 |
| 16 | China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.
The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first on SecurityWeek.
https://www.securityweek.com/china-and-us-agree-to-establish-ai-safety-channel-and-continue-trade-and-military-talks/ | 38 |
| 17 | OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/openais-ai-agents-accidentally-uploaded-user-provided-images-to-third-party-sites/ | 43 |
| 18 | GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]
https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/ | 42 |
| 19 | Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/ | 53 |
| 20 | Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/claude-opus-55-uses-95-percent-fewer-em-dashes-but-its-answers-are-getting-longer/ | 52 |
