The IT week was the box on the internet. Two NetScaler RCEs on KEV; last week’s Check Point “imminent” is exploited; SharePoint was recast from spoofing.
21–28 September 2026. Twelve new KEVs. Citrix 88771 is unauthenticated command execution on every customer-managed ADC. Check Point 85102, last week’s unexploited VPN, is now catalog. SharePoint, WordPress, and MikroTik are due today.
Executive summary
FACT: Last week the highest-leverage enterprise problem was the box that admits other boxes — ISE for who is on the network, SEG for what mail gets in, vCenter for which VMs exist. This week the same class moved one hop outward: the appliance that is the internet path, and the application that sits on it without a WAF that actually matches the exploit.
CISA’s Known Exploited Vulnerabilities catalog, version 2026.09.27 released 27 September 21:30 UTC, now holds 1,728 rows. Twelve of those were added between 21 and 27 September. Eleven carry forensic triage Yes. One — MikroTik CVE-2026-67279 — is No. Catalog ransomware-use on every new row is Unknown. The material ransomware increment this week is not a new CVE. It is a campaign on an old one: Mandiant/GTIG on 26 September, UNC6240 (ShinyHunters) resumed mass exploitation of PeopleSoft CVE-2026-35273, KEV since 12 June, ransomware-use already Known.
Citrix published CTX697096 on 27 September. Two of eight CVEs — CVE-2026-88771 and CVE-2026-88772 — went on KEV the same day. Federal clock 30 September. 88771 is unauthenticated command execution on every customer-managed ADC and Gateway, including default configuration. There is no feature to turn off. The August NetScaler build that closed CVE-2026-19490 sits inside today’s affected range.
Last week this briefing wrote that Check Point CVE-2026-85102 / CVE-2026-85103 was still not exploited on the vendor record. That sentence is now wrong for 85102. CISA listed it 22 September. Check Point: Spark-targeted attempts from 12 September, certificates with subjects CN=vpn / CN=vpn-user / CN=vpnuser. CVE-2026-85103 is still not in the catalog. CVE-2026-91843 is still not in the catalog. A third Check Point row is: CVE-2026-93616, management path traversal, exploited as a zero-day since 23 July per the vendor, LivePatch Take 28/29 does not close it.
Due today, 28 September: SharePoint CVE-2026-65660, WordPress Core CVE-2026-87902, MikroTik CVE-2026-67279. Due Wednesday: the two NetScaler RCEs.
ASSESSMENT: If the patch queue this week was last week’s ISE/SEG/vCenter leftovers plus the 974 Microsoft CVEs, you sequenced it backwards again. NetScaler is the WAN side of the identity path. Check Point 85102 is the VPN last week’s NCSC-NL “imminent” has become. SharePoint’s August spoofing ticket is authenticated RCE with a Monday clock.
The week in one assessment
Three threads, one pattern: attackers keep buying the box that terminates the other boxes — NetScaler for SSL VPN and ICA, Check Point for IKE, F5 APM for OAuth tokens, Arista VCO for SD-WAN Edges — while the internet-facing enterprise apps (SharePoint recast from spoofing, WordPress core include, WSO2 JWT, PeopleSoft with a one-character WAF bypass) prove that a catalog row from June or a Magento hotfix from August is not a closed incident.
1. Most important development
Citrix NetScaler. It is not a load balancer in this story. It is the WAN-side identity and application path: SSL VPN, ICA/CVPN, AAA, the VIP in front of internal apps. Unauthenticated command execution there is code execution on the box that holds certificates, session state, and a view of what is behind it.
Citrix CTX697096, created 27 September 15:22. Two sentences matter more than the eight-row table: exploits of CVE-2026-88771 and CVE-2026-88772 “have been observed” on unmitigated deployments. And: 88771 hits all ADC/Gateway deployments, “including those deployed with the default configuration. No additional features or settings need to be enabled.”
Do not collapse four facts.
- 88771 and 88772 are not the same precondition. 88771 is CWE-20 (Citrix/CVE.org; KEV JSON lists CWE-119 on both rows — use the CNA for class). Unauthenticated arbitrary commands. No extra feature. 88772 is CWE-119 memory overflow that needs DTLS enabled. Citrix: DTLS is on by default on VPN virtual servers.
add vpn vserver … SSL …without-dtls OFFmeets 88772. Turning DTLS off does not close 88771. - The August NetScaler patch does not close this. CVE-2026-19490 (KEV due 12 September) fixed in 14.1-73.32 / 13.1-63.21. Those builds sit inside 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23.
- A firmware ISO is not forensic triage. CISA’s dedicated 27 September alert: check for compromise before patching. Citrix Console IoC scan needs 14.1-73.36+ and telemetry on. Citrix’s own caveat: a clean scan is not proof.
- CISA’s language is global. Partner threat intelligence, “actively exploiting these vulnerabilities globally.” No named actor. Ransomware-use Unknown. Shadowserver’s ~23,000 NetScaler fingerprints, as restated by BleepingComputer, is a banner census, not a vulnerable-version count.
Fixed trains: 14.1-73.37, 13.1-64.23, matching FIPS/NDcPP floors. No published workaround for 88771/88772. The other six CVEs in the same bulletin are not KEV; CVE-2026-88778 is closed by Enhanced ISN Generation, not by the upgrade alone.
There is no confirmed OT or physical-process impact. A NetScaler in front of an industrial remote-access path is still an IT perimeter compromise until evidence says otherwise. We do not have it.
2. Active exploitation
CONFIRMED in KEV this window, catalog 2026.09.27:
| Added | CVE | Product | Due | Forensic triage | Ransomware |
|---|---|---|---|---|---|
| 21 Sep | CVE-2026-7273 | Zyxel GS1900 CGI overflow | 24 Sep | Yes | Unknown |
| 22 Sep | CVE-2026-85102 | Check Point Gateway / Spark VPN | 25 Sep | Yes | Unknown |
| 22 Sep | CVE-2026-93616 | Check Point management / log / SmartEvent | 25 Sep | Yes | Unknown |
| 22 Sep | CVE-2026-93952 | Arista VeloCloud Orchestrator on-prem | 25 Sep | Yes | Unknown |
| 22 Sep | CVE-2026-94127 | F5 BIG-IP APM OAuth AS | 25 Sep | Yes | Unknown |
| 24 Sep | CVE-2026-5430 | WSO2 API Manager / Control Plane / TM / UG | 27 Sep | Yes | Unknown |
| 24 Sep | CVE-2026-71362 | Adobe Commerce / Magento | 27 Sep | Yes | Unknown |
| 25 Sep | CVE-2026-65660 | Microsoft SharePoint Server | 28 Sep | Yes | Unknown |
| 25 Sep | CVE-2026-87902 | WordPress Core | 28 Sep | Yes | Unknown |
| 25 Sep | CVE-2026-67279 | MikroTik RouterOS | 28 Sep | No | Unknown |
| 27 Sep | CVE-2026-88771 | Citrix NetScaler ADC / Gateway | 30 Sep | Yes | Unknown |
| 27 Sep | CVE-2026-88772 | Citrix NetScaler (DTLS) | 30 Sep | Yes | Unknown |
The twelfth row is not the twelfth story. Zyxel is adjacent-scored LAN CGI with GreyNoise’s 996-switch collection as the counter to AV:A. Adobe 71362 is customer-session ATO from APSB26-92 (11 August); Adobe’s bulletin still said it was not aware of in-the-wild exploits when CISA listed it. MikroTik 67279 is the unauthenticated session-channel half of a chain to CVE-2026-86060 (KEV since 10 September). All three are real KEV rows. None of them is the WAN-side identity appliance.
Check Point 85102 is. Vendor confirmation this week, not last week’s NCSC-NL forecast: Spark attempts from 12 September, anonymization infrastructure, three certificate subjects. LivePatch Take 26 (or Jumbo R81.20 Take 166 / R82 Take 126 / R82.10 Take 44 / R81.10 Take 190) is the current SK instruction. Take 24 was the 9 September close for some trains; some offline LivePatch packages still need 26. 85103 is still not KEV.
CVE-2026-93616 is the management sibling that is not 91843. Path traversal, unauthenticated script exec on Security Management / MDS / Log / SmartEvent. Vendor: handful of customers, 23 July. sk1000171. LivePatch Take 28/29 closed 91843. It does not close 93616.
F5 CVE-2026-94127: heap overflow, CVSS 9.8, data plane, appliance mode in. F5 narrowed the CNA at 00:45 UTC 23 September to OAuth Authorization Server only. CISA’s shortDescription still says “access policy and an OAuth profile.” Inventory the role, not the module checkbox. Closing the management port does not close the VIP. March’s APM KEV CVE-2025-53521 builds sit inside this range. iRule first for triage, then ENG hotfix 21.1.0.2.0.30.22 / 17.5.1.9.0.160.12 / 17.1.3.5.0.41.14. Clock expired 25 September. Forensic triage has not.
Arista CVE-2026-93952: CVSS 10.0, on-prem VCO, certificate-based Edge auth plus VCO web UI. Hosted already patched. Vendor floors 5.2.3.16 / 6.4.2.8. 6.1 and 7.0 still have no listed fix in the advisory we have been citing. Clock expired 25 September.
WSO2 CVE-2026-5430: vendor primitive is CWE-347 JWT algorithm mismatch, unauthenticated account takeover including admin, WSO2-2026-5328 (3 May), CVSS 10.0. CISA’s vulnerabilityName and shortDescription still say path traversal / unrestricted file upload / RCE. Same JSON object lists CWE-347. Treat the vendor as the bug and CISA as the clock. watchTowr honeypot forged admin JWTs 13 September. Clock expired 27 September.
SharePoint CVE-2026-65660: Microsoft shipped it 11 August as spoofing 6.5; recast 27 August to CWE-94 authenticated RCE, CVSS 8.8. CISA listed it 25 September. Microsoft Current Exploitation Status 25 September: reliable evidence of observed attacks. Due today. On-prem 2016 / 2019 / Subscription Edition. SharePoint Online is not in the affected list. Previdian honeypot: webshell /_layouts/15/sphealth.aspx. One honeypot is not a victim census.
WordPress CVE-2026-87902: 7.1.2 on 22 September, backports to 4.7.37. Unauthenticated get_page_template() include. Patchstack: probes 22 September 11:49 UTC; 23 September file writes via pearcmd.php under /tmp and /var/tmp. CISA listed it 25 September. Due today. /tmp drops are not durable web shells per Patchstack. They are still RCE telemetry.
CONFIRMED exploited, not a new KEV row: PeopleSoft CVE-2026-35273. Already KEV since 12 June, due 15 June, ransomware-use Known, forensic triage No. Mandiant/GTIG 26 September: UNC6240 resumed mass exploitation by asking for /%50SEMHUB/ instead of /PSEMHUB/. %50 is the letter P. Literal-path WAF rules miss it. Dozens of web shells; SIDEEYE (Ple64.exe), Neo-reGeorg, MeshAgent. Sectors named include higher education, technology, IT services, healthcare, agriculture, transportation, government. Agriculture and transportation here are PeopleSoft customer sectors, not process impact.
CONFIRMED exploited, still not in KEV: CVE-2026-58138 in Orkes / conductor-oss Conductor. Unauthenticated GraalVM RCE. Same status as last week. Named actor: UNKNOWN.
NOT exploited, on the record: Check Point CVE-2026-91843 (management login stack overflow, Take 28/29). Still not catalog. CVE-2026-85103 still not catalog.
3. Threat actor / campaign activity
No new Talos FMC cluster this window. Last week’s UAT-12197 / UAT-11823 (Sandworm-tooling overlap, not a named GRU attribution) / UAT-11988 (Qilin) remain the attributed exploitation on the firewall manager. This week’s Citrix, F5, Check Point, WSO2, and SharePoint KEVs did not come with a cluster name.
UNC6240 did. Mandiant/GTIG, 26 September: the June PeopleSoft campaign is back as an N-day with a WAF-bypass encoding. Cluster name is Mandiant’s, with ShinyHunters as the public label. RWP is not independently attributing. FBI Jobs / a second PSEMHUB zero-day remain actor claims in secondary reporting; Mandiant’s 26 September post does not name the FBI. Steal-then-leak extortion in Mandiant’s September picture is not a named encryptor, even though the KEV ransomware field has been Known since June.
GreyNoise’s GS1900 collection (996 switches / 48 countries / 564 factory defaults / US 129, on or about 17 August) is CONFIRMED as GreyNoise telemetry, not a CISA census, and not merged with WordPress. CISA did not name GreyNoise on the 7273 row.
Jade Sleet FLATROOF/ROOFDECK on the Indian IT-services Mac was last week’s nation-state item. No material second-victim increment published in this window.
PaperCut’s GreyNoise campaign (440 / 395 / 12 domain admin) did not publish a material second-wave increment. The 14 September KEV clock is long expired. The hunt is not.
Kiteworks’ 25 September precautionary six-hour shutdown, citing law-enforcement / federal intelligence, is REPORTED as a vendor ask. No CVE. Vendor: no confirmed compromise. Evidence quality is too thin to lead a week.
4. Vulnerabilities to prioritize
Order is reachability and post-exploit value, not CVSS.
- Citrix NetScaler CVE-2026-88771 / 88772 — unauthenticated, default-config (88771), DTLS-on-VPN (88772), forensic triage Yes, due 30 September. Hunt before the ISO. 14.1-73.37 / 13.1-64.23. August 19490 builds are still in.
- Check Point CVE-2026-85102 — now KEV, clock expired 25 September, forensic triage Yes. Take 26 or listed Jumbo. Spark: R82.00.10 Build 2325+ / R81.10.17 Build 4968+. Hunt the three CN subjects. 85103 is still a sibling, still not catalog, still in the same certificate class — take it in the same change window.
- Check Point CVE-2026-93616 — management path traversal, July zero-day, clock expired 25 September. sk1000171. Do not apply Take 28/29 and call this closed.
- F5 BIG-IP APM CVE-2026-94127 — OAuth Authorization Server VIP, data plane, clock expired 25 September, forensic triage Yes. iRule then ENG hotfix. Inventory the role.
- SharePoint CVE-2026-65660 — due today. August 11 updates. Recast from spoofing. Hunt
sphealth.aspxand the usual_layoutsdrop paths. On-prem only. - WordPress CVE-2026-87902 — due today. 7.1.2 or the backport. Hunt pearcmd writes under
/tmpand/var/tmp, then the web root. - WSO2 CVE-2026-5430 — clock expired 27 September. JWT alg mismatch, not the path-traversal string in the KEV title. Patch to WSO2-2026-5328 levels. Rotate admin tokens.
- Arista VCO CVE-2026-93952 — clock expired 25 September. Hosted is vendor-patched. On-prem 6.1 / 7.0 still wait. Pull WAN from unfixed trains.
- PeopleSoft CVE-2026-35273 — June KEV, September WAF bypass. The literal
/PSEMHUB/rule is not the patch. Hunt SIDEEYE, MeshAgent, Neo-reGeorg. Rotate whatever the hub could see. - MikroTik CVE-2026-67279 — due today, forensic triage No, chain to 86060. Zyxel 7273 clock expired 24 September; firmware
2.90(*.2)C0shipped in June — hunt default admin anyway. - Adobe CVE-2026-71362 — clock expired 27 September. APSB26-92. Customer-session ATO, not StyleSmuggler’s template RCE. Different Magento row, same store.
- Conductor CVE-2026-58138 — still exploited, still no KEV row. 3.30.2 or later.
Check Point 91843 stays on the unexploited-same-class list. Artifactory 42016 / 42018 clocks expired 25 September. Linux kernel trio clocks expired 21 September. None of those is this week’s lead.
5. Identity / cloud / enterprise
NetScaler and F5 APM are the identity incidents. A Gateway that already ran unauthenticated commands is an alternate path around every Conditional Access policy that assumes the VPN concentrator is trustworthy. An APM authorization server that already took a heap overflow is an alternate path around every token-issuance assumption. Rotate VPN accounts, AAA stores, certificates on the box, and anything the appliance used to join AD. iACLs after the fact do not unscrew a re-image you skipped.
WSO2 is the API identity incident: a forged admin JWT is not “a gateway bug.” It is administrative takeover of the control plane that issues tokens to every other API. CISA’s path-traversal title will send scanners after the wrong primitive. Hunt issued tokens, not upload paths.
SharePoint is the document-plane identity incident the second time: authenticated low-priv to RCE on the server that holds internal files. Microsoft’s original-publication exploitability table still showing Exploited: No is a page fact. The 25 September Current Exploitation Status line is the vendor confirmation. Treat both as on-page; act on the second.
PeopleSoft PSEMHUB is the ERP identity incident: Environment Management Hub, unauthenticated since June, now walking past the WAF string operators substituted for the patch. Rotate PS credentials, integration accounts, and whatever SIDEEYE could reach.
UNC6240’s MeshAgent overlap with last week’s Huntress Settra picture is tooling coincidence until someone produces a join. We do not have it. Do not merge the two.
Artifactory tokens, GitLab deploy keys, and Conductor’s open API remain the non-human-identity remainder. Their clocks expired. The hunt did not.
6. Ransomware / criminal activity
CONFIRMED by CISA, unchanged this window: ransomware-campaign use of vCenter CVE-2026-59310 (Known since 16 September) and TeamCity CVE-2026-63077 (Known since 5 August). BleepingComputer’s 24 September TeamCity restatement is not a field flip. Family unnamed on both.
CONFIRMED by CISA catalog field, not by a new encryptor this week: PeopleSoft CVE-2026-35273 ransomware-use Known since June. Mandiant’s 26 September picture is steal-then-leak. Do not invent a locker.
CONFIRMED last week, still in force: Talos UAT-11988 as a Qilin affiliate on FMC via CVE-2026-20316.
All twelve new KEV rows this week: ransomware-use Unknown. Do not import last year’s NetScaler ransomware history onto 88771.
PaperCut KEV ransomware-use remains Unknown. Domain admin on a school-district print server is still a ransomware precondition. No new GreyNoise increment past 440.
Do not convert an IT compromise at an agricultural or transportation PeopleSoft customer into confirmed OT impact. Mandiant named sectors. That is ERP access at industrial-adjacent organizations until someone produces process evidence. We do not have it.
7. Defensive priorities
- Internet-facing NetScaler ADC/Gateway, Check Point Gateway/Spark VPN, Check Point management (93616, not 91843), F5 APM OAuth AS, Arista on-prem VCO, SharePoint Server, WordPress, WSO2, PeopleSoft PSEMHUB, leftover ISE / SEG / vCenter / FMC / N-central / ScreenConnect / PaperCut / GitLab / Magento / Artifactory / Conductor. If it terminates sessions from WAN, it is this week’s ticket.
- Forensic triage is the instruction on eleven of twelve new rows. Patching without the hunt is how you leave a NetScaler implant, a Spark VPN shell, a TMM SIGABRT follow-on, a SharePoint layout drop, or a WSO2 admin JWT in place.
- NetScaler: 14.1-73.37 / 13.1-64.23 and compromise assessment before the ISO. Console IoC is first-pass, not proof. DTLS off is 88772 only.
- Check Point VPN: Take 26 or listed Jumbo and the three CN subjects. Spark has its own builds. 85103 in the same window.
- Check Point management 93616: sk1000171, not Take 28/29. 91843 still wants 28/29. Three CVEs, three takes.
- F5 APM: inventory Authorization Server VIPs. iRule, then ENG hotfix. Management-port closure is not the control.
- SharePoint: August 11 build and
_layoutshunt. Due today. - WordPress: 7.1.2 and pearcmd/
/tmphunt. Due today. - WSO2: advisory levels and token rotation. Ignore the KEV title’s file-upload string for hunting.
- PeopleSoft: patch, then decode-aware WAF, then SIDEEYE/MeshAgent hunt. Literal
/PSEMHUB/is not remediation.
8. What changed from last week
Last week’s [weekly IT](/posts/2026-09-21-weekly-it-identity-plane-ise-seg-vcenter/) was ISE (TAC-found CVSS 10 API), SEG (crafted email → root), vCenter ransomware-use Known, Linux kernel trio due 21 September, Check Point 91843 unexploited, Conductor exploited-not-KEV, Jade Sleet on an IT-services Mac.
This week those open items closed or moved as follows:
- Check Point 85102 is now KEV and vendor-confirmed exploited from 12 September. Last week’s “still not exploited” sentence is retired for 85102 only. 85103 is still not KEV.
- Check Point 91843 is still not KEV and still not exploited on the vendor record. The new management KEV is 93616, a different primitive, a different SK, and Take 28/29 does not close it.
- Linux kernel trio federal clocks expired 21 September. No named implant class published against kTLS/ebtables/AF_ALG this window.
- Artifactory 42016/42018 clocks expired 25 September. Ransomware Unknown, forensic triage No. No material second-wave increment.
- Conductor 58138 is still exploited and still has no KEV row.
- PaperCut did not grow a published victim increment past 440.
- Jade Sleet did not publish a named customer follow-on. Delivery on the Indian host remains UNKNOWN.
- ISE 76460 and SEG 76461 clocks remain expired. No Cisco actor or IoC set beyond “TAC case.”
- vCenter 59310 ransomware-use remains Known. Family still unnamed.
- The target class moved outward: last week the NAC, the mail parser, and the hypervisor; this week the ADC, the VPN, the OAuth VIP, the SD-WAN orchestrator, and the internet-facing app whose August ticket said spoofing.
- Catalog count 1716 → 1728. Twelve adds in seven days, versus seven the week before.
9. What we are watching next
Whether Citrix or CISA names an actor, a victim increment, or ransomware-use on 88771/88772 before Wednesday’s clock. Whether 13.1-64.24 (watchTowr reboot-loop note) lands in CTX697096. Whether Check Point 85103 or 91843 follows 85102/93616 into KEV. Whether Arista publishes 6.1 / 7.0 fixes. Whether Microsoft’s SharePoint original-publication “Exploited: No” table is brought in line with the 25 September status line. Whether WordPress pearcmd /tmp writes become durable web roots at scale. Whether WSO2’s KEV title is corrected to CWE-347. Whether Conductor 58138 lands in KEV. Whether UNC6240’s encoded-path trick shows up in other PSEMHUB-adjacent WAFs, or in a named encryptor. Whether GreyNoise or PaperCut publish a second-wave increment. Whether GitLab 85706 produces a documented secrets-to-supply-chain case. Chromium’s next in-the-wild after 85046 and 87491.
10. RWP assessment
Confidence: High on the KEV listing set (catalog 2026.09.27, count 1728), on Citrix’s observed exploitation of 88771/88772 as described, on Check Point’s 12 September Spark attempts and 23 July 93616 zero-day as vendor statements, on Microsoft’s 25 September SharePoint exploitation status, and on Mandiant/GTIG’s encoded-path PeopleSoft campaign as written. Moderate on unifying NetScaler, Check Point VPN, F5 APM, and Arista VCO into a single “perimeter campaign” — the pattern is target class, not actor. Moderate on UNC6240 as ShinyHunters for the September wave (Mandiant’s cluster; RWP is not independently attributing). Low on remaining unpatched internet population (Shadowserver banners are not version counts; GreyNoise 996 is one vendor’s telemetry). None claimed on OT process impact.
The week does not require a new SIEM use-case. It requires the boxes that terminate other boxes — NetScaler, Check Point VPN, F5 APM OAuth AS, on-prem VCO — to be patched, hunted, and pulled off WAN, and the IdP to assume that a Gateway, an ADC, or a SharePoint farm can already mint a trusted path.
This assessment covers 21–28 September 2026 and was published 28 September 2026.
Sources
- CISA — KEV catalog JSON catalogVersion 2026.09.27
- CISA — Adds one KEV 21 September 2026
- CISA — Adds four KEVs 22 September 2026
- CISA — Adds two KEVs 24 September 2026
- CISA — Adds two KEVs 25 September 2026
- CISA — Adds one KEV 25 September 2026
- CISA — Adds two KEVs 27 September 2026
- CISA — Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC, Gateway
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Citrix — CTX697096 NetScaler CVE-2026-88771 through CVE-2026-88778
- Citrix — Community bulletin CVE-2026-88771 through CVE-2026-88778
- CVE — CVE-2026-88771
- CVE — CVE-2026-88772
- CERT-EU — Security Advisory 2026-014
- Check Point — sk1000117 CVE-2026-85102
- Check Point — sk1000171 CVE-2026-93616
- Check Point — Advisory on 85102 and 93616
- BleepingComputer — Check Point warns of hackers exploiting Security Gateway VPN RCE
- F5 — K000162605 BIG-IP APM CVE-2026-94127
- CVE — CVE-2026-94127
- CERT-EU — Security Advisory 2026-013
- Arista — Security Advisory 0183 CVE-2026-93952
- Microsoft — CVE-2026-65660 Security Update Guide
- WSO2 — WSO2-2026-5328 / CVE-2026-5430
- WordPress — GHSA-7hp8-65ch-5whp
- Mandiant / GTIG — ShinyHunters renewed mass exploitation of Oracle PeopleSoft
- Adobe — APSB26-92
- GreyNoise — Open Season on Kapibala
- MikroTik — September 2026 vulnerability
- RWP — Daily Top Zyxel GS1900
- RWP — Daily Top F5 APM
- RWP — Daily Top WordPress
- RWP — Daily Top WSO2
- RWP — Daily Top SharePoint
- RWP — Daily Top PeopleSoft
- RWP — Daily Top NetScaler
- RWP — Weekly IT 21 September 2026