Back Defendwork Citrix NetScaler, Oracle, Cloudflare RCEs under active exploitation; WAF bypasses escalate risks
Two critical Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are actively exploited in attacks; patches released. Oracle PeopleSoft CVE-2026-35273 exploitation surges via WAF bypass tricks. Cloudflare patches container isolation flaw exposing multi-tenant data.
Citrix confirmed two NetScaler RCE zero-days under active exploitation; security updates released September 27, with federal remediation deadline September 30.
ShinyHunters extortion gang escalates Oracle PeopleSoft campaign using URL-encoding bypass to evade web application firewall mitigations, resuming mass exploitation.
Cloudflare patched a cross-tenant isolation flaw in Containers and Sandboxes allowing paid customers to recover residual data from other customers’ containers.
Lunex malware-as-a-service platform abuses AMD kernel drivers to disable endpoint security while stealing browser credentials via compromised Ukrainian websites.
1. Citrix NetScaler RCE Zero-Days Actively Exploited
Severity: CRITICAL Affected: Technology Government
Citrix has confirmed two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway are being actively exploited in the wild [1] [2] . CVE-2026-88771 involves improper input validation allowing unauthenticated attackers to execute arbitrary commands [4] , while CVE-2026-88772 is a buffer overrun flaw enabling RCE or denial of service [3] . One of the flaws affects every deployment on an affected version [1] . Citrix released security updates on September 27, 2026 ⚠ [1] [2] , with CISA setting a federal remediation deadline of September 30, 2026 [3] [4] . Sources: [1] The Hacker News [2] BleepingComputer [3] CISA KEV [4] CISA KEV
Immediately apply Citrix security patches to all NetScaler ADC and Gateway instances; prioritize this as a network-critical update ahead of the September 30 federal deadline
If patches cannot be deployed immediately, isolate affected NetScaler instances or restrict inbound access to trusted networks only
Monitor NetScaler logs for exploitation indicators including unexpected command execution or authentication bypass attempts
Verify patch deployment across all NetScaler deployments in your estate before September 30
2. ShinyHunters Resumes Oracle PeopleSoft Mass Exploitation via WAF Bypass
Severity: HIGH Affected: Technology
Google has warned of renewed mass exploitation of CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft, involving the ShinyHunters-linked extortion gang [1] . The threat actors are using URL-encoding bypass tricks to evade web application firewall (WAF) rules designed to mitigate the vulnerability, allowing widespread exploitation to resume on unpatched servers [2] . The critical flaw could result in remote code execution and web shell deployment across multiple sectors globally [1] . Sources: [1] The Hacker News [2] BleepingComputer
Patch Oracle PeopleSoft to the latest available version to close CVE-2026-35273; if patching is delayed, apply WAF rules and monitor for URL-encoded payloads in addition to standard filtering
Review PeopleSoft logs for successful exploitation attempts, particularly looking for unusual command execution or file creation post-authentication
If breach is suspected, assume credential theft and web shell persistence; conduct forensic analysis for backdoors
Increase monitoring of PeopleSoft environments for reconnaissance activity and lateral movement
3. Cloudflare Container Cross-Tenant Data Exposure Patched
Severity: HIGH Affected: Technology
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers running on the same physical host [1] . The flaw represented a multi-tenant isolation bypass, exposing ephemeral data and potentially sensitive computation artifacts to lateral enumeration. Sources: [1] BleepingComputer
Verify that your Cloudflare Workers Paid account has received the container isolation patch; check your account settings for confirmation
If you use Cloudflare Containers for sensitive workloads, audit your container logs for any indicators of unauthorized data access during the vulnerability window
Review any secrets, credentials, or sensitive data that may have been processed in containers during the vulnerability period
4. Lunex Malware Platform Abuses AMD Drivers; ClickFix Distribution Observed
Severity: HIGH Affected: Technology
The Psychedelic Stealer malware, distributed via compromised Ukrainian websites using ClickFix-style fake Cloudflare verification checks, is part of a wider malware-as-a-service ⚠ (MaaS) platform called Lunex [1] . Lunex abuses AMD kernel drivers to disable endpoint security monitoring and steal browser credentials [1] . The attack chain involves four stages and targets users via social engineering on legitimate-appearing verification pages. Sources: [1] The Hacker News
Update endpoint detection and response (EDR) tools to detect AMD driver exploitation and unsigned kernel module loading attempts
Educate users to verify domain URLs carefully before clicking on verification pages; legitimate platforms do not require re-verification via pop-up checks
Monitor for suspicious AMD driver-related process execution and disable unnecessary AMD driver services where possible
Isolate infected systems and reset browser credentials, particularly targeting authentication tokens for financial and email accounts
Today’s Action Checklist
☐ URGENT: Apply Citrix NetScaler patches to all ADC and Gateway instances before September 30 deadline
☐ URGENT: Patch Oracle PeopleSoft CVE-2026-35273; implement enhanced WAF rules for URL-encoded payload detection if patching is delayed
☐ HIGH: Verify Cloudflare Containers patch deployment if using Workers Paid tier
☐ HIGH: Update EDR and antimalware signatures to detect Lunex/Psychedelic Stealer and AMD driver abuse
☐ HIGH: Scan logs for exploitation of Citrix NetScaler, Oracle PeopleSoft, and suspicious AMD driver activity
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
