top of page

Cybersecurity Weekly Roundup: 21-28 September 2026

Writer: SOC Team
SOC Team
1 hour ago
4 min read

1. Citrix NetScaler Zero-Days Actively Exploited in the Wild


Two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in attacks. Citrix confirmed the vulnerabilities after security researchers and cybersecurity agencies warned organisations that attackers were targeting vulnerable appliances.

The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. The first is an unauthenticated remote code execution vulnerability affecting NetScaler ADC and Gateway deployments, while the second is a memory-overflow vulnerability that can allow remote code execution or denial-of-service attacks when DTLS is enabled. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue.

CVE ID: CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5)


Why It Matters: NetScaler appliances frequently sit at the network perimeter and provide remote access and application delivery services. Successful exploitation could provide attackers with access to infrastructure that handles external connections into corporate environments, potentially creating a pathway to internal systems and sensitive resources.

Actions: Apply the latest Citrix security updates immediately. Review internet-facing NetScaler appliances for indicators of compromise before and after patching. Review appliance and network logs for suspicious command execution, unusual administrative activity, unexpected outbound connections and other anomalous behaviour. Where immediate patching is not possible, restrict access to trusted networks and follow Citrix's emergency mitigation guidance.


2. Microsoft SharePoint Vulnerability Now Exploited in Attacks


A critical Microsoft SharePoint Server vulnerability is now being exploited in attacks, roughly six weeks after Microsoft released security updates. Microsoft confirmed that it had reliable evidence of exploitation as of 25 September, while threat intelligence researchers observed attempts to create webshell backdoors.

Tracked as CVE-2026-65660, the vulnerability is a code-injection flaw that allows an authenticated attacker with low-level privileges to execute arbitrary code on an affected SharePoint server without user interaction. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 25 September.

CVE ID: CVE-2026-65660 (CVSS 8.8)


Why It Matters: SharePoint is widely used by organisations to store and manage sensitive documents and business information. Successful exploitation could allow attackers to execute code on SharePoint infrastructure and potentially use the compromised server to access sensitive data, establish persistence or move further into the internal environment.

Actions: Apply Microsoft's security updates to affected SharePoint Server deployments immediately. Review SharePoint servers for unexpected webshells, newly created files, suspicious process execution and unusual authentication activity. Monitor outbound connections from SharePoint servers and investigate unexpected administrative activity. If exploitation is suspected, conduct a compromise assessment and review potentially exposed credentials before closing the incident.


3. Ransomware Groups Now Exploiting Critical JetBrains TeamCity Flaw


CISA has warned that ransomware groups are exploiting a critical vulnerability in JetBrains TeamCity, a platform used by software development and DevOps teams to automate building, testing and deployment.

Tracked as CVE-2026-63077, the vulnerability is an authentication bypass that can allow an unauthenticated attacker with HTTP(S) access to execute arbitrary operating system commands with the privileges of the TeamCity server process. Depending on the server's privileges, exploitation could expose stored credentials and configurations and allow attackers to modify build processes and downstream CI/CD pipelines.

CVE ID: CVE-2026-63077 (CVSS 9.8)


Why It Matters: CI/CD infrastructure can provide access to source code, deployment credentials, cloud environments and production systems. Compromising TeamCity could therefore allow attackers to move beyond the development environment or manipulate software build and deployment processes.

Actions: Upgrade affected TeamCity On-Premises deployments to the latest fixed versions immediately. Restrict TeamCity access to trusted networks and administrators. Review TeamCity server and agent logs for suspicious authentication activity, unexpected command execution, newly created accounts and configuration changes. If compromise is suspected, rotate credentials and secrets accessible from the TeamCity environment and review build pipelines for unauthorised modifications.


4. F5 BIG-IP APM Zero-Day Exploited in Remote Code Execution Attacks


F5 has released security updates for a critical BIG-IP Access Policy Manager (APM) vulnerability that has been exploited in remote code execution attacks. The vulnerability affects BIG-IP APM instances configured as an OAuth Authorization Server with an APM access policy and OAuth profile configured on a virtual server.

Tracked as CVE-2026-94127, the vulnerability can be exploited remotely without authentication. F5 has advised organisations to investigate systems showing multiple OAuth authentication failures followed by suspicious commands and a TMM process crash. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalogue.

CVE ID: CVE-2026-94127 (CVSS 9.8)


Why It Matters: BIG-IP APM provides centralised access management for networks, applications, cloud environments and APIs. A successful compromise could therefore affect infrastructure responsible for controlling access to business-critical resources and potentially provide attackers with a foothold at the network perimeter.

Actions: Apply F5's security updates immediately to affected BIG-IP APM deployments. Review BIG-IP logs for repeated OAuth authentication failures, suspicious commands, unexpected process crashes and unusual administrative activity. Review firewall and network telemetry for unexpected connections originating from affected appliances. Where patching cannot immediately be completed, implement F5's recommended mitigation measures.


Key Recommendations


  • Prioritise actively exploited vulnerabilities: Review exposure to CVE-2026-88771, CVE-2026-88772, CVE-2026-65660, CVE-2026-63077 and CVE-2026-94127 and apply the relevant security updates as a priority.

  • Secure internet-facing infrastructure: Give particular attention to Citrix NetScaler and F5 BIG-IP APM, as these platforms can sit at the network perimeter and provide remote access or authentication services.

  • Protect development infrastructure: Review the exposure of TeamCity and other CI/CD platforms, particularly where they contain deployment credentials, API keys or access to production environments.

  • Monitor for exploitation: Review SIEM, endpoint and network telemetry for suspicious command execution, webshell creation, authentication anomalies, new accounts, configuration changes and unusual outbound connections.

  • Review privileged credentials: Where an affected system may have been compromised, investigate and rotate credentials or secrets that were accessible from the affected system.

  • Reduce external exposure: Restrict management interfaces and administrative services to trusted networks wherever operationally possible.

  • Investigate before closing incidents: Patching removes the vulnerability but does not necessarily remove persistence established during earlier exploitation. Conduct a compromise assessment where exploitation is suspected.

  • Prioritise exploitation status alongside CVSS: Vulnerabilities with confirmed exploitation should receive urgent attention, particularly when they affect internet-facing, centrally managed or security-critical infrastructure

 
 
bottom of page