Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: edge-appliance (4 articles)Clear

Citrix confirms two NetScaler remote code execution zero-days exploited in active attacks

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks, and released fixes. These are the same zero-days that researchers, IT providers, and national cyber agencies warned about privately over the weekend, with some advising immediate NetScaler shutdowns. Organizations commonly deploy NetScaler as internet-facing edge devices for remote access and application delivery, so compromising one gives attackers a foothold at the network perimeter and a potential path to internal systems without first landing on an internal endpoint. CISA added the flaws to its Known Exploited Vulnerabilities catalog with a near-term federal patch deadline.

Check
Identify all internet-facing NetScaler appliances, apply Citrix's fixed builds immediately, and hunt for compromise indicators given confirmed active exploitation.
Affected
Unpatched internet-facing NetScaler appliances face active exploitation of two remote code execution zero-days, handing attackers a foothold at the network perimeter.
Fix
Patch NetScaler to Citrix's fixed versions now, restrict management exposure, review sessions and logs, and treat exposed devices as potentially compromised.

Attackers plant a stealthy Linux rootkit on F5 BIG-IP access gateways

Researchers at Sophos and ESET found attackers breaching F5 BIG-IP APM access gateways and installing a stealthy Linux rootkit that ESET calls PoisonedRefresh. Rather than dropping a file on disk, it hides a web shell in memory, hooks into the Apache and PHP components, tampers with SELinux settings, and uses disguised requests to run commands while blending into normal traffic. Crucially, it persists across device upgrades, so patching the appliance alone does not remove it. The intrusions likely began by exploiting a critical remote code execution flaw that F5 had earlier downgraded to a mere denial-of-service issue, which may have led some organizations to deprioritize patching it.

Check
Treat internet-facing F5 BIG-IP APM devices as potentially compromised, patch the underlying remote code execution flaw, and hunt for in-memory web shells, Apache and PHP hooks, and altered SELinux settings.
Affected
Organizations running F5 BIG-IP APM access gateways, especially internet-facing ones on the vulnerable version; attackers install a memory-resident rootkit that survives upgrades and turns the gateway into a persistent, covert foothold.
Fix
Patch the F5 flaw, but because the rootkit survives upgrades, inspect and rebuild affected devices from known-good images, restrict management exposure, rotate credentials the gateway handled, and re-evaluate vendor DoS-only ratings.

Critical Citrix NetScaler flaw lets attackers bypass authentication on gateways

Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.

Check
Upgrade NetScaler ADC and Gateway to the fixed builds immediately, and check your configuration for SAML action, gateway, and AAA virtual server entries to gauge exposure, treating edge appliances as priority targets.
Affected
Organizations running affected Citrix NetScaler ADC or Gateway as a gateway or AAA server (CVE-2026-19490); a remote, unauthenticated attacker can bypass authentication and reach internal services normally protected by it.
Fix
Patch to the fixed NetScaler versions, review configurations against Citrix's exposure criteria, monitor these appliances closely for compromise given their history as targets, and restrict management and gateway exposure where possible.

Critical Kemp LoadMaster flaw gives unauthenticated attackers root on edge appliances

A critical flaw in Progress Kemp LoadMaster lets an unauthenticated attacker run commands as root on the appliance by sending a crafted request to its API. Rated 9.8, the bug (CVE-2026-8037) sits in a function meant to sanitize input before it reaches a shell command, and LoadMaster's position as an edge load balancer and application delivery controller makes a pre-authentication flaw especially dangerous, since it can turn a protective choke point into a direct foothold. Progress patched it in early June, and researchers at watchTowr published a full technical write-up with a working proof-of-concept on June 29. No exploitation has been reported yet, but Progress also makes MOVEit, a past mass-exploitation target.

Check
Identify Progress Kemp LoadMaster appliances with the API enabled, confirm their versions, and determine whether the management API is reachable from untrusted networks or the internet, the exposure this flaw needs.
Affected
Kemp LoadMaster GA 7.2.63.1 and earlier and LTSF 7.2.54.17 and earlier with the API enabled (CVE-2026-8037); an unauthenticated attacker who can reach the API gains root on an edge device.
Fix
Update to LoadMaster GA 7.2.63.2 or LTSF 7.2.54.18, and question whether the management API needs to be reachable at all, restricting it to trusted management networks or disabling it where unused.