⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories.

Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.
Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.
Citrix released patches for vulnerabilities numbered CVE-2026-88771 through CVE-2026-88778 on Sunday, and confirmed that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” CVE-2026-88771 stems from improper input validation and allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices running a default configuration.
The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities: The NCSC recommends following vendor best practice advice to mitigate vulnerabilities.
CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service.
Hackers exploit Gyazo server flaw to steal 23.6 million user records Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing about 23.62 million user records and metadata tied to hundreds of millions of images.
The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.
Cybersecurity and Infrastructure Security Agency (CISA), on September 25, 2026, added CVE-2026-87902, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 28, 2026.
What happened
Citrix Warns of Actively Exploited NetScaler ADC and Gateway Flaws — Citrix released patches to address multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, that have come under active exploitation.
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.
What changed
Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.
Who is affected
Citrix released patches for vulnerabilities numbered CVE-2026-88771 through CVE-2026-88778 on Sunday, and confirmed that “exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” CVE-2026-88771 stems from improper input validation and allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices running a default configuration.
The following supported versions of customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities: The NCSC recommends following vendor best practice advice to mitigate vulnerabilities.
Why it matters
CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands, while successful exploitation of CVE-2026-88772 could allow for remote code execution or denial-of-service.
Hackers exploit Gyazo server flaw to steal 23.6 million user records Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing about 23.62 million user records and metadata tied to hundreds of millions of images.
Technical details
The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.
Cybersecurity and Infrastructure Security Agency (CISA), on September 25, 2026, added CVE-2026-87902, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 28, 2026.
CISA said "threat actors are actively exploiting these vulnerabilities globally," urging federal agencies to apply patches by Wednesday.
Response
While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers.
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
What security teams should do
Citrix acknowledged that, since threat actors change techniques, tactics, and procedures and infrastructure frequently, the indicators of compromise they used “might fail to identify actual compromises,” so customers should “retain the services of experienced forensic investigators to assess [their] environment.” The US Cybersecurity and Infrastructure Security Agency (CISA) added the two actively exploited flaws to its Known Exploited Vulnerabilities catalog on Sunday and ordered US federal civilian agencies to address them by Wednesday (September 30, 2026) and perform forensic triage to check for evidence of compromise.
The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.
Attribution
The Hacker News: A domain used as harmless placeholder text showed up in roughly 1,700 repositories.
NCSC-UK: The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Help Net Security: Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices.
The Hacker News: Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.