Skip to content
Citrix NetScaler Zero-Days, PeopleSoft WAF Bypasses & SharePoint Exploits - Rod's Blog

Citrix NetScaler Zero-Days, PeopleSoft WAF Bypasses & SharePoint Exploits - Rod's Blog

Rodtrent.Substack • September 27, 2026

Security firm watchTowr reported on September 26 that two new, still-unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited in the wild. These are distinct from the earlier authentication-bypass issue (CVE-2026-19490) that Citrix patched in August and that CISA later added to its Known Exploited Vulnerabilities catalog.

NetScaler appliances commonly sit at the network edge handling VPN, remote access, load balancing, and authentication—making them high-value targets. Citrix has not yet confirmed the flaws, issued CVEs, published indicators of compromise, or released patches. Some administrators have taken appliances offline as a precaution while waiting for official guidance. Exploitation details remain limited, but the credible reporting and forensic origins of the discovery have put organizations with internet-facing NetScaler instances on high alert. Defenders are advised to inventory exposed appliances, restrict access where possible, monitor for anomalous sessions or configuration changes, and prepare for rapid patching once Citrix responds.

ShinyHunters Resume Oracle PeopleSoft Attacks with Simple WAF Bypass

Google’s Mandiant and Threat Intelligence Group warned of a renewed mass-exploitation campaign by the ShinyHunters-linked group (UNC6240) against Oracle PeopleSoft. Attackers are again weaponizing the critical unauthenticated remote code execution flaw CVE-2026-35273 (CVSS 9.8), first exploited as a zero-day earlier in 2026.

The latest twist is a lightweight WAF bypass: instead of requesting the vulnerable /PSEMHUB/ endpoint, they use a URL-encoded variant such as /%50SEMHUB/. Many web application firewalls and reverse proxies that match on the literal path miss the request, while PeopleSoft decodes it and processes it normally. Successful exploitation leads to deployment of JSP web shells (e.g., x.jsp, u.jsp), the SIDEEYE backdoor, tunneling tools, and MeshCentral agents for persistence and lateral movement. Targets span higher education, technology, healthcare, government, and other sectors. The clear recommendation remains the same: apply Oracle’s patch rather than relying solely on path-blocking WAF rules, disable or remove the Environment Management Hub where feasible, and hunt logs for both plain and encoded path variants.

CISA Adds Actively Exploited SharePoint RCE and MikroTik RouterOS Flaws to KEV Catalog

On September 25–26, CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation: CVE-2026-65660 (Microsoft SharePoint code injection / remote code execution, CVSS 8.8) and CVE-2026-67279 (MikroTik RouterOS improper enforcement of behavioral workflow).

CVE-2026-65660 was originally described by Microsoft in its August Patch Tuesday updates as a lower-severity spoofing issue. Microsoft later updated the advisory to reflect remote code execution impact after authenticated (low-privilege) attackers were observed exploiting it, including attempts to drop web shells. Federal agencies face a short remediation window (deadline around September 28). The MikroTik flaw allows an unauthenticated client to open a session channel and send an exec request. Both entries reinforce the ongoing risk of edge and collaboration platforms. Organizations should prioritize patching SharePoint Server (2016, 2019, Subscription Edition) and affected RouterOS versions, review exposure, and hunt for signs of post-exploitation activity.

These three stories highlight a familiar pattern: high-value edge and enterprise platforms remaining under sustained pressure from both sophisticated extortion groups and opportunistic exploiters, with defenders often racing between incomplete mitigations and official fixes.

Discussion this post