Our weekly round-up of significant threats and actively exploited vulnerabilities. It is awareness content, not a monitored threat intelligence service: always check vendor advisories against your own environment.
This week at a glance
Edge devices are again the main target. Critical flaws in Citrix NetScaler and Check Point VPN gateways are being actively exploited, and a WordPress core flaw is being used to compromise websites. Apple has also patched a zero-day used in targeted attacks. If you run any of these products, patching should be this week’s priority.
Actively exploited vulnerabilities
Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772)
Two critical flaws allow unauthenticated remote code execution. The second requires DTLS, which is enabled by default on VPN virtual servers. Citrix confirms exploitation, and the NCSC has issued an alert. Attackers have deployed web shells and moved laterally in government, financial, legal, and professional services organisations. Fix: upgrade to 14.1-73.37 or 13.1-64.23 (or the listed FIPS/NDcPP builds), then check for signs of compromise.
Sources: Citrix bulletin CTX697096; NCSC alert
Check Point Security Gateway and Management (CVE-2026-85102, CVE-2026-93616)
A certificate validation flaw in VPN negotiation allows pre-authentication remote code execution on gateways running Site-to-Site or Remote Access VPN, and a separate path traversal affects the Management web service. Both have been exploited and were added to CISA’s Known Exploited Vulnerabilities (KEV) catalogue on 22 September. Fix: apply the Jumbo Hotfix for your branch as listed in Check Point’s advisory.
Source: Check Point advisory
WordPress core (CVE-2026-87902)
A flaw in page-template handling allows unauthenticated attackers to include local PHP files, leading to remote code execution in some configurations. It is being exploited to plant malicious files. Fix: update to WordPress 7.1.2 or the patched release for your branch; automatic background updates should already have applied it.
Source: WordPress 7.1.2 release
Microsoft SharePoint Server (CVE-2026-65660)
A code injection flaw in on-premises SharePoint Server 2016, 2019, and Subscription Edition allows remote code execution, and can be chained with an authentication bypass. Exploitation began after technical details were published, and CISA added it to KEV on 25 September. Fix: the August 2026 security updates.
Source: SecurityWeek
MikroTik RouterOS (CVE-2026-67279 and CVE-2026-86060)
An SSH authentication bypass chained with privilege escalation gives attackers full administrative access to internet-exposed routers. Fix: upgrade to the latest RouterOS 6.49 or 7.x build, as some early patches were incomplete.
Source: CERT Polska
Apple iOS, iPadOS, and macOS (CVE-2026-86950)
A CoreGraphics flaw allowing code execution through a crafted file may have been used in highly targeted attacks. Fix: iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1.
Source: BleepingComputer
Notable threats and campaigns
Attacks on unpatched Oracle PeopleSoft
Mandiant warns that the ShinyHunters group is targeting organisations that applied workarounds for an Oracle PeopleSoft vulnerability but not the June patch, planting web shells and stealing HR, payroll, and student data for extortion. Workarounds are not a substitute for patching.
Source: The Record
ClickFix attacks through malicious custom GPTs
Sponsored search results led users to a malicious custom ChatGPT that directed them to a fake verification page, tricking them into running PowerShell commands that installed a remote access trojan. It is a reminder to include “paste this command” lures in awareness training.
Source: BleepingComputer
Other patches worth knowing
- F5 BIG-IP APM (CVE-2026-94127) and Arista VeloCloud Orchestrator (CVE-2026-93952): added to KEV on 22 September.
- WSO2 (CVE-2026-5430) and Adobe Commerce/Magento (CVE-2026-71362): added to KEV on 24 September.
- Zyxel GS1900 switches (CVE-2026-7273): firmware available for all affected models.
Practical steps to consider
- Check whether you run any of the affected products, especially internet-facing VPN and remote access appliances, and patch as a priority.
- For exploited edge devices, patching alone is not enough: look for indicators of compromise and reset credentials where advised.
- Review how quickly critical patches reach your systems, and whether your ISO/IEC 27001 vulnerability management (Annex A 8.8) and Cyber Essentials security update requirements are being met in practice.
This round-up is for general awareness only and is not a monitored threat intelligence service. If you would like help reviewing your vulnerability management or incident readiness, contact us.