important1 finding, 16 signals, 2 noted5 min read

Active exploitation has turned two unauthenticated NetScaler flaws into current perimeter execution.

An internet caller can reach an affected NetScaler virtual server without credentials.

Priority findings1
§
High
Edge
Confirmed
CVE-2026-88771

Actively exploited NetScaler flaws give unauthenticated internet callers code execution on perimeter gateways.

Citrix confirms exploitation of both paths on unmitigated deployments.

Affects

Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery, VPN, and remote-access appliances

What it enables

Unauthenticated remote code execution on an enterprise perimeter gateway

An unauthenticated caller reaches a NetScaler deployment in its default configuration, or a DTLS-enabled virtual server.→↓Crafted input reaches the improper-validation path in CVE-2026-88771 or the DTLS memory-overflow path in CVE-2026-88772.→↓The appliance executes attacker-controlled commands or code; Citrix confirms exploitation of both flaws on unmitigated deployments.
Why this matters

The change is current exploitation: a caller without credentials can now cross a deliberately deployed perimeter boundary through either of two code-execution paths.

Detail, proof-of-concept code and 7 sources
Required access

Internet reachability to an affected NetScaler virtual server; no credentials. CVE-2026-88772 additionally requires DTLS, which is enabled by default on VPN virtual servers.

Affected versions

14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1-FIPS before 14.1-73.37 FIPS, 13.1-FIPS and 13.1-NDcPP before 13.1-37.279, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS, NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279, NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

Internet reachability to an affected virtual server is sufficient; CVE-2026-88772 additionally needs DTLS, which is enabled by default on VPN virtual servers.

CVE-2026-88771 reaches attacker-controlled commands through improper input validation, while CVE-2026-88772 reaches code execution through a DTLS memory overflow.

Citrix says both flaws are being exploited on unmitigated systems.

Fixes are available, but complete revocation of pre-fix NetScaler images has not been established.

Evidence
Citrix states both primitives and confirms exploitation on unmitigated deploymentsPublic exploit or independent technical reproduction
Share this finding
Signals16
important · Zero-click

An iMessage EXR attachment reaches privileged background processing without a tap and causes attacker-controlled heap corruption.

Affects

Apple iOS and iPadOS devices whose background photo-processing services automatically decode EXR attachments received through iMessage.

The decoder allocates 12 bytes per RGB pixel and writes 16 attacker-controlled bytes, after Messages and the photo subsystem route the unopened attachment into libAppleEXR.

Detail and 3 sources

The researcher reached arbitrary write and program-counter control in a harness, but did not demonstrate clean cross-process code execution because the remaining path requires a PAC-signed pointer.

Apple has fixed the ImageIO flaw.

Chain to watch
Gain an information leak or PAC bypass in the privileged background process→↓Convert the controlled overwrite into clean cross-process execution→↓Test the path on hardware with and without Memory Integrity Enforcement→↓Clean code execution in the real privileged process remains unproven, and hardware protections change the result.
Unverified chainDemonstrate an information leak or PAC bypass in the real process and test across protected and unprotected hardware generations.
important · Research

WordPress page-template traversal can lead to conditional unauthenticated PHP execution.

Affects

WordPress Core, the PHP content-management system used by public websites.

A valid page_id and double-encoded traversal can make template resolution include readable PHP outside the active theme.

Detail and 3 sources

Code execution additionally requires a qualifying theme layout, a usable local inclusion target, PEAR, and register_argc_argv; under those conditions pearcmd.php can write PHP that a second request executes as the web-server account.

WordPress has published a fix.

important · Privilege

An empty signature list can make Authlib accept attacker-authored JWS content as authenticated.

Affects

Authlib, a cross-platform Python library used by web applications and microservices for OAuth, OpenID Connect, JWT and JWS handling.

The general-JSON deserializer begins in a successful state and performs no verification loop iteration when signatures is empty, so it returns an unsigned payload as verified.

Detail and 2 sources

A relying application can turn that result into forged identities, roles, scopes, inter-service messages, or configuration.

Public code demonstrates the bypass, no patch is available in the reviewed material, and we do not know how commonly applications expose this Authlib path.

Chain to watch
An application accepts JWS general JSON through Authlib→↓Authlib accepts an empty signatures array without verification→↓The application trusts the returned payload for authentication or authorization→↓Deployment of the affected general-JSON path is unknown.
Unverified chainInventory Authlib consumers that accept JWS general JSON and reject objects with no signatures at the application boundary.
important · Mobile

One malicious deep-link click can leak a Wikipedia Android user's long-lived Wikimedia credentials to an attacker domain.

Affects

Wikipedia for Android, the Wikimedia reading application running on Android phones and tablets.

Suffix-only hostname and cookie checks accept a domain such as evil-wikipedia.org, load it in the app's WebView, and attach Wikimedia cookies.

Detail and 1 source

The attacker receives the username, long-lived token, and session token, which permit account takeover across Wikimedia projects.

The user must already be logged in and click the supplied wikipedia:// link.

important · Edge

A public Zimbra Briefcase document can become unauthenticated command execution as the zimbra account.

Affects

Zimbra Collaboration Suite mail and collaboration servers with OnlyOffice or Document Editing available.

An anonymous caller needs the URL of an existing supported public document on a server with OnlyOffice or Document Editing enabled.

Detail and 3 sources

Unsigned save fields permit path-traversal writes outside the document location, producing command execution under the zimbra service identity.

Zimbra has published a fix.

important · Privilege

PHP-FPM's exact-client IPv6 ACL admits any host in an allowed client's /96.

Affects

PHP-FPM, the FastCGI process manager shipped with PHP on Unix-like web servers.

The check compares only 12 of 16 address bytes, so a nearby IPv6 host can pass listen.allowed_clients and submit FastCGI requests to accessible PHP scripts.

Detail and 1 source

Exposure requires an IPv6-reachable TCP listener and an attacker address sharing the configured client's first 96 bits; patched releases exist for every supported branch.

important · Privilege

FreeRDP can leave active smart-card and generated private keys readable by another local account.

Affects

FreeRDP, an RDP client/server implementation and toolkit on Linux and other Unix-like systems.

Under a common 022 umask, private-key files could inherit permissions broad enough for another user on a shared Unix host to read an active temporary copy or traversable output file.

Detail and 3 sources
important · Firmware

Network access to a WatchGuard AP internal API is sufficient for unauthenticated shell-command execution.

Affects

WatchGuard AP wireless access points running WatchGuard AP software.

The management API contains command injection, while a separate access-control flaw can issue a valid API session without credentials.

Detail and 2 sources

The practical boundary is API reachability: the caller must be able to connect to the access point's internal service.

WatchGuard has published corrected firmware.

important · Privilege

Disabling a WeKan account did not revoke its API or attachment access.

Affects

WeKan, a self-hosted collaborative kanban server commonly deployed in containers.

REST login ignored loginDisabled, and existing bearer or cookie tokens remained usable after an administrator disabled the identity.

Detail and 2 sources
important · RCE

A malicious webpage can make an npm-installed OpenCode server install an attacker package and run its lifecycle script.

Affects

OpenCode, a cross-platform local coding-agent server and web interface.

A top-level text/plain form navigation avoids a CORS preflight and supplies a remote package URL to the local upgrade endpoint.

Detail and 2 sources

npm, pnpm, or Bun then installs the package and executes its lifecycle script as the OpenCode user; cached Basic credentials can preserve the path even when the server is password protected.

The corrected release rejects the reproduced request with HTTP 415 and limits upgrade targets to semantic versions.

important · RCE

One unauthenticated multipart filename executes commands on HFS 2.4, outside the older 2.3m CVE scope.

Affects

Rejetto HTTP File Server 2.x, a Windows file-sharing web server.

The filename enters a rejected-upload response, survives sequential template substitution, escapes a quoting region, and exposes an exec macro to the dispatcher.

Detail and 3 sources

Public Python and Nuclei reproducers were reported to work repeatedly against the original 2.4 RC7 binary, and upload permission is unnecessary.

This is a distinct sink from CVE-2024-23692, and no patch is available.

important · RCE

A malformed password can execute JScript in hMailServer when JScript password-validation events are enabled.

Affects

Progressive Robot hMailServer, a Windows SMTP, POP3 and IMAP mail server.

A backslash followed by an apostrophe can close the generated password string and inject JScript before authentication succeeds.

Detail and 2 sources

The path requires a known active username and the non-default OnClientValidatePassword JScript hook.

The upstream correction ships in hMailServer 6.3.4.

important · Firmware

A LAN peer can bypass the Netcore NR289-GE web login and execute commands as root.

Affects

Netcore NR289-GE, an embedded SMB router and wireless access-point controller.

Placing .ico before a CGI path bypasses both Boa and CGI permission checks, exposing handlers that interpolate form values into root shell commands.

Detail and 3 sources
important · Wi-Fi

Buffalo's authenticated web command injection also reaches the WEX-G300 extender.

Affects

Buffalo WEX-G300, a consumer Wi-Fi range extender running embedded firmware.

An attacker with administrator credentials and configuration-interface access can escape a web-form field into an operating-system command.

Detail and 1 source
important · Wi-Fi

Unauthenticated requests can crash management services on Buffalo WSR-300HP and WEX-G300 devices.

Affects

Buffalo WSR-300HP Wi-Fi routers and WEX-G300 Wi-Fi range extenders running embedded firmware.

Crafted input reaches a stack-based overflow without authentication and puts the management service into a denial-of-service state.

Detail and 1 source

The management interface must be reachable, and internet exposure requires optional remote access.

Buffalo has published fixed versions.

important · Mobile

Apple patched a CoreGraphics crafted-file code-execution flaw after reports of targeted exploitation.

Affects

CoreGraphics in supported iPhones and iPads running the iOS 26 branch; Apple also shipped corresponding macOS fixes

CVE-2026-86950 is an out-of-bounds write in CoreGraphics that can execute code when an affected device processes a crafted file.

Detail and 4 sources

Apple says it is aware of possible exploitation against specifically targeted individuals.

Apple has not disclosed the file format, delivery channel, victim interaction, processing context, victims, or post-execution privilege.

Apple fixed the flaw in current supported updates.

Chain to watch
Attacker supplies a maliciously crafted file through an undisclosed delivery path→↓CoreGraphics processes the file→↓An out-of-bounds write corrupts memory→↓Arbitrary code executes in the processing context→↓The triggering format, delivery route, interaction requirement, processing context, victims, and post-execution privilege remain undisclosed; zero-click reachability is not established.
Unverified chainObtain Meta's technical analysis or incident forensics identifying the triggering format, delivery route, process, and interaction requirement.
Also noted2
Firmware
WatchGuard AP firmware before 3.4.8 permits unauthenticated internal-API shell execution.
Install 3.4.8, but do not assume WAN reach or root execution: the listener binding and resulting identity are undisclosed.
ResearchWatchGuard Security Advisories
Firmware
A factory-default Netcore NBR100V2 accepts anonymous Ubus writes that persist Wi-Fi and update settings.
Keep untrusted peers off the setup network after deployment and after resets; no patch is available.
Code / PoCHACKALL/netcore_NBR100V2_V1.3.240614.030928 Router/netcore_nbr100v2_uci_config_tamper.md at main · senxitoyshuyi-ui/HACKALL
What was checked · 3 quiet
Boot chain & TPMQuiet

No new signed-component revocation, bootloader control-flow proof, Secure Boot bypass, TPM key-recovery path, or U-Boot execution proof was established.

BluetoothQuiet

Recent Linux and BlueZ activity added assignments, stable-version bookkeeping, tests, and packaging for known flaws without a new Bluetooth primitive.

Physical accessQuiet

No recent event widened physical-access capability; the malicious-HID Linux kernel primitive predates this daily window.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026