Back Myitforum.Substack IT Pros Weekly Roundup September 28 -October 2, 2026
Five days. A NetScaler pair that was already owned before the bulletin existed. A Cisco SD-WAN Manager that hands out admin if you encode the URL just so. SharePoint quietly from “spoofing” to remote code execution. And an agentic crew that treats Azure service principals like rental cars. If the weekend plan was “we’ll patch Monday,” Monday already happened.
Edge and identity: the appliances that run the front door
Citrix NetScaler zero-days were exploited before the patches existed. On September 26, researchers warned that two remote code execution flaws in NetScaler ADC and Gateway were already in use. Citrix confirmed both the day in bulletin CTX697096. CVE-2026-88771 (CVSS 9.5) is unauthenticated command execution on customer-managed ADC and Gateway, including default configuration. CVE-2026-88772 (CVSS 9.5) is a memory overflow via DTLS, on by default on VPN virtual servers. CISA added both to the KEV catalog the same day, with a federal deadline of September 30. Fixed builds in coverage: 14.1-73.37 and later, and 13.1-64.23 and later, plus the matching FIPS trains. Government and finance organizations were among those hit before disclosure. Patch, then hunt. A clean upgrade does not scrub a box that was already compromised.
Timeline and KEV deadline
Timeline and KEV deadline
Cisco Catalyst SD-WAN Manager authentication bypass, no workaround. CVE-2026-76504 (CVSS 9.8) is improper handling of URI encoding in the Manager API. A remote, unauthenticated attacker can send a crafted HTTP request and land as admin. Every configuration is affected. Cisco PSIRT learned of exploitation in September and published the advisory on September 30. CISA added it to KEV the same day. Fixed releases include 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1. Earlier than 20.9 means migrate. There is no config toggle that removes the exposure.
CISA on X, September 30
CISA on X, September 30
Check Point management server and F5 BIG-IP APM are still in the assume-breach pile. CVE-2026-93616 (CVSS 9.8) is a pre-auth path traversal in Check Point Security Management Server. Check Point said a handful of customers were hit; exploitation dates back to July, with emergency fixes on September 22. CVE-2026-94127 (CVSS 9.8) is unauthenticated RCE in F5 BIG-IP Access Policy Manager when APM is an OAuth authorization server. Both landed on CISA KEV with a three-day federal clock.
Innovate Cybersecurity top 10, September 28
Innovate Cybersecurity top 10, September 28
Telefónica Tech briefing, September 19–25
Telefónica Tech briefing, September 19–25
Microsoft estate: ratings lie, queues do not
SharePoint CVE-2026-65660 got reclassified, six weeks late. Microsoft shipped the fix on August 11 and called it spoofing (their score 6.5). NVD scored it 8.8. On September 25, CISA put it on KEV as code injection that lets a low-privilege authenticated user run code with no further interaction. Federal deadline: September 28. Exploitation attempts were reported from September 24, with web shells the day. Vendor severity is a hint, not a schedule.
September’s patch mountain is still the operational story. Counts vary by tracker — 966, 972, 974 — but every serious write-up agrees this was the largest Microsoft monthly batch on record, with two exploited privilege-escalation zero-days (Windows Update Stack CVE-2026-81963 and ALPC CVE-2026-85880) and on the order of 20 wormable-class issues, including a Windows DNS Server RCE that drew SigRed comparisons. Year-to-date Microsoft fixes are past 2,760. Out-of-band follow-ups also had to mop up Patch Tuesday side effects: Remote Desktop hangs, Credential Guard machine accounts, dead audio, and Excel 2016 paste failures.
The Cloud Pod, September 24
The Cloud Pod, September 24
Record-batch breakdown
Record-batch breakdown
Mail, cloud, and the agent problem
Zimbra CVE-2026-73570 is still being worked in the wild. Microsoft Threat Intelligence published on September 30 on unauthenticated OS command injection in the Zimbra Collaboration Suite SNMP notification path. A crafted SMTP message is enough when the optional zimbra-snmp package is installed and SNMP notifications are on. Follow-on activity included JSP web shells, reverse shells, and mailbox theft. The fix has been in Zimbra 10.1.20 since July 20.
Microsoft Security Blog
Microsoft Security Blog
Microsoft Threat Intelligence on X
Microsoft Threat Intelligence on X
JadePuffer / Storm-3168 used stolen Azure identities to delete the furniture. Microsoft’s September 25 write-up expands the first documented agentic ransomware operator into destructive Azure activity. Compromised service principals enumerated VMs and resource groups, then ran bulk destructive and credential-collection operations. Treat non-human identities like privileged users.
Cloudflare Containers had a cross-tenant residue bug. A Workers Paid customer could recover leftover data from another customer’s container on the same host. Rotate anything that lived in those environments.
BleepingComputer cloud coverage
BleepingComputer cloud coverage
AWS bulletins worth a ticket. September 29: CVE-2026-100308, arbitrary command execution during GluonTS model deserialization. September 24: CVE-2026-96883 in AWS pgcollection, and CVE-2026-95985, Kiro IDE agentic writes to global config from untrusted workspaces.
AWS security bulletins
AWS security bulletins
Desktop agents are now in the threat model. Objective-See flagged CVE-2026-100754: ChatGPT’s code-signing checks on macOS and Windows can be bypassed by a local, unprivileged attacker, who then inherits the agent’s trust.
Patrick Wardle on X, September 30
Patrick Wardle on X, September 30
ShinyHunters claimed an FBI breach via an Oracle PeopleSoft zero-day , with talk of movement into FBI-managed AWS GovCloud. The FBI said it is investigating unauthorized activity on FBIjobs.gov. Treat the claim as unverified, and unpatched internet-facing PeopleSoft as verified risk. Innovate Cybersecurity, September 28
ShinyHunters claimed an FBI breach via an Oracle PeopleSoft zero-day , with talk of movement into FBI-managed AWS GovCloud. The FBI said it is investigating unauthorized activity on FBIjobs.gov. Treat the claim as unverified, and unpatched internet-facing PeopleSoft as verified risk. Innovate Cybersecurity, September 28
Other CISA KEV additions in this window included WSO2 API Manager JWT bypass (CVE-2026-5430), Adobe Commerce / Magento (CVE-2026-71362), Arista VeloCloud Orchestrator (CVE-2026-93952), and a MikroTik RouterOS SSH bypass. Same Innovate roundup.
Other CISA KEV additions in this window included WSO2 API Manager JWT bypass (CVE-2026-5430), Adobe Commerce / Magento (CVE-2026-71362), Arista VeloCloud Orchestrator (CVE-2026-93952), and a MikroTik RouterOS SSH bypass. Same Innovate roundup.
SolarWinds patched unauthenticated RCE in Observability Self-Hosted (CVE-2026-28324 and CVE-2026-28325) on September 24. SecurityWeek
SolarWinds patched unauthenticated RCE in Observability Self-Hosted (CVE-2026-28324 and CVE-2026-28325) on September 24. SecurityWeek
Kiteworks lifted a shutdown advisory on September 29 after patching a critical flaw. BleepingComputer
Kiteworks lifted a shutdown advisory on September 29 after patching a critical flaw. BleepingComputer
Industry letter: more than 100 companies, including OpenAI, Anthropic, AWS, Google, and Microsoft, warned that AI-assisted attack tooling is shrinking the time between disclosure and exploitation. Cloud Pod notes
Industry letter: more than 100 companies, including OpenAI, Anthropic, AWS, Google, and Microsoft, warned that AI-assisted attack tooling is shrinking the time between disclosure and exploitation. Cloud Pod notes
Do this before the stand-up
NetScaler ADC/Gateway to CTX697096 fixed builds, then compromise assessment on anything internet-facing before September 27.
NetScaler ADC/Gateway to CTX697096 fixed builds, then compromise assessment on anything internet-facing before September 27.
Cisco Catalyst SD-WAN Manager to a fixed release. No workaround. Check API logs.
Cisco Catalyst SD-WAN Manager to a fixed release. No workaround. Check API logs.
SharePoint: confirm the August CVE-2026-65660 fix is deployed, not merely approved.
SharePoint: confirm the August CVE-2026-65660 fix is deployed, not merely approved.
Zimbra: if zimbra-snmp is installed, confirm 10.1.20 or later and hunt the Microsoft IOCs.
Zimbra: if zimbra-snmp is installed, confirm 10.1.20 or later and hunt the Microsoft IOCs.
Azure: review service-principal Owner and Contributor assignments and alert on mass delete.
Azure: review service-principal Owner and Contributor assignments and alert on mass delete.
Keep chewing the September Microsoft backlog, zero-days and DNS first.
Keep chewing the September Microsoft backlog, zero-days and DNS first.
The vulnerability count went up, the CVSS labels went down, and the attackers did not read either.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
