important1 finding, 9 signals, 2 noted4 min read

An indirect prompt injection can induce an agent to reproduce the injection in its outgoing messages or files. OpenAI demonstrated email, filesystem, and multi-hop Slack propagation in controlled evaluations. CVE-2026-88771 and CVE-2026-88772 provide unauthenticated code-execution paths on affected customer-managed NetScaler appliances. Citrix and the Canadian Cyber Centre report exploitation of both flaws on unmitigated customer deployments.

The propagation behavior turns an agent-generated outbound artifact into a delivery channel for the next indirect prompt injection. CVE-2026-88771 uses improper input validation to permit arbitrary commands in every affected deployment, including the default configuration. CVE-2026-88772 is a DTLS-reachable memory overflow that can cause code execution or denial of service, and DTLS is enabled by default on VPN virtual servers.

Priority findings1
§
High
Edge — RCE
Confirmed
CVE-2026-88771

Two exploited NetScaler zero-days give unauthenticated network callers code execution on the appliance.

One arbitrary-command path is present in default deployments; the other is a memory overflow behind DTLS, which is enabled by default on VPN virtual servers.

Affects

NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.

What it enables

Unauthenticated code execution on a customer-managed NetScaler appliance

Reach a customer-managed NetScaler ADC or Gateway virtual service over the network without credentials.→↓For CVE-2026-88771, send input to the vulnerable path present in every deployment, including the default configuration; alternatively, reach a DTLS-enabled service for CVE-2026-88772.→↓Improper input validation permits arbitrary commands, or the DTLS memory overflow yields remote code execution.→↓Execute code in the appliance service context; Citrix says exploitation of both flaws has been observed on unmitigated deployments.
Why this matters

These are pre-authentication paths through default or normally enabled services, and exploitation was observed before unmitigated customers had closed them.

Detail and 3 sources
Required access

Network reachability to a customer-managed NetScaler ADC or Gateway service; CVE-2026-88771 affects default configurations, while CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers

Affected versions

NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS 14.1 before 14.1-73.37 FIPS, NetScaler ADC FIPS and NDcPP 13.1 before 13.1-37.279

A network caller can reach CVE-2026-88771 without credentials or an optional feature and execute arbitrary commands through improper input validation. On a DTLS-enabled service, CVE-2026-88772 can turn crafted traffic into code execution or denial of service through a memory overflow.

Citrix has published fixed builds for the affected NetScaler versions.

Evidence
Citrix's bulletin identifies both unauthenticated execution primitives, their deployment preconditions, affected versions, fixed builds and observed exploitationCitrix's accompanying threat-intelligence post confirms exploitation on unmitigated deployments and states that CVE-2026-88771 needs no optional featureThe Canadian Cyber Centre independently reports exploitation across multiple customer environmentsNo public exploit code or researcher reproduction was located
Share this finding
Signals9
important · SharePoint — RCE

Attackers are composing anonymous SharePoint delivery with CVE-2026-65660 to install a server-side web shell.

Affects

Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.

On an anonymously viewable on-premises site missing the separate June delivery fix, a WebPartPage route reaches ToolPane processing without authentication. Quote injection then bypasses SafeControls validation and enters attacker-controlled .NET deserialization.

Detail and 3 sources

Observed payloads disable a deserialization safeguard, load an embedded assembly, and create /_layouts/15/sphealth.aspx as a persistent web shell.

Move to a listed fixed build and verify that the separate June anonymous-delivery correction is also present before permitting anonymous access.

important · Signal for iOS

A removed Signal group member can rewrite their own recent message in one victim’s local iOS view.

Affects

Signal for iOS, the encrypted messaging client running on iPhone and iPad

The attacker must have authored the message, retain its timestamp and a one-to-one session with the recipient, and send the edit within 48 hours. Omitting groupV2 context routes the edit through the contact thread, while a thread-blind lookup finds and overwrites the old group message.

Detail and 2 sources
important · SolarWinds ARM

A universal SolarWinds ARM secret turns TCP/55555 reachability into LocalSystem execution.

Affects

SolarWinds Access Rights Manager, enterprise identity-governance software running on Windows servers.

The listener permits TLS without a client certificate, and the shipped key mints its fallback authentication token. ARM then borrows a locally registered identity and accepts a .NET Remoting message at a BinaryFormatter sink.

Detail and 3 sources
important · Signal for iOS

A registered Signal user can alter pin and poll state in an unrelated group on one victim’s iPhone.

Affects

Signal for iOS, the encrypted messaging client running on iPhone and iPad

Signal authorizes the sender against an attacker-selected contact thread, then uses a global thread-blind index to resolve an interaction in another group. That permits recipient-local pin removal or corruption and an unauthorized poll vote.

Detail and 2 sources

The attacker needs the target message’s timestamp and author ACI, which is most practically learned through former group membership. Signal 8.7.0.1523 is identified as the fixed release.

important · Sylius

A Sylius customer account can become an administrator by sharing an administrator’s email address.

Affects

Sylius, a PHP e-commerce framework used by self-hosted online shops.

On a shop with self-registration enabled, an attacker who knows an administrator email can register that address, obtain a Shop API JWT, and present it to the Admin API. Because tokens were not bound to their firewall or principal type, the Admin API resolves the email to the administrator.

Detail and 4 sources
important · Embedded firmware

Public emulation code routes Seetong recorder TCP/3000 commands to a root shell.

Affects

Seetong TS81xxD3X-family embedded video recorders using the iDVR 9000 firmware platform.

The extracted firmware binds the plaintext debug listener to all interfaces, and Cmd input reaches /bin/sh in a UID 0 process under emulation.

Detail and 2 sources

The researcher tested no physical recorder, so stock listener exposure and the complete model mapping remain unverified.

Chain to watch
Confirm TCP/3000 bindings on stock T8108, T8108P, T8116, and T8232 hardware.→↓Send a benign identity command through the documented Cmd protocol.→↓Record firmware build, listener interfaces, and process credentials.→↓Execution is established only against extracted firmware under emulation; stock exposure and model coverage remain unresolved.
Unverified chainTest the named stock models with a benign identity command while recording listener bindings, firmware build, and process UID.
important · Embedded firmware

Public firmware-emulation code shows unauthenticated NBR200V2 requests reaching a root shell.

Affects

Netcore NBR200V2, an embedded business router managed through its uHTTPd web interface.

The network-tools handler evaluates attacker-controlled diagnostic input before checking authentication, and the emulated web service runs as root.

Detail and 2 sources

Firmware configuration lists uHTTPd on ports 80, 443, and 23355, but stock-hardware execution and default WAN reachability have not been established.

Chain to watch
Confirm the listening interfaces on a stock NBR200V2 running V1.3.241127.071246.→↓Send a benign unauthenticated network-tools request containing a shell metacharacter.→↓Record authentication behavior, command output, and process UID.→↓The published execution result comes from QEMU or chroot rather than stock hardware, and default WAN exposure is unknown.
Unverified chainReproduce a benign identity command on stock hardware while capturing listening interfaces and resulting UID.
important · Bluetooth

A Botslab G980H exposes protected Wi-Fi credential material to an unpaired BLE client.

Affects

Botslab G980H dash cameras, embedded in-vehicle recording devices with BLE provisioning and a local Wi-Fi network.

The newly understood link is in the firmware: a hard-coded key and initialization vector provide a provisional path from the BLE-readable credential to the Wi-Fi password.

Detail and 1 source

We do not have public evidence of end-to-end decryption using a credential captured from a named shipping unit, and plaintext recovery also requires the matching firmware image.

Chain to watch
Capture the protected credential from a shipping G980H over an unpaired BLE connection.→↓Extract the key and initialization vector from the matching firmware build.→↓Decrypt the credential and verify that the recovered password joins the dashcam network.→↓The BLE read and firmware constants have not been joined in a public end-to-end reproduction on a named shipping unit.
Unverified chainAcquire a matching firmware build, capture the BLE credential, and test whether the recovered plaintext joins the camera network.
important · Agent security

An indirect prompt injection can reproduce through an agent’s outgoing messages and files.

Affects

Internal OpenAI agent research checkpoints operating with email, Slack, filesystem, and connector tools.

Attacker-authored email, Slack content, or a file can be retrieved during an ordinary agent task, redirect tool or output behavior, and get copied into a message or persistent file that another agent later reads.

Detail and 1 source

The demonstrations stayed inside controlled evaluations, affected internal-only checkpoints, and produced no observed impact outside simulated tool calls.

Also noted2
Wi-Fi routers
An unauthenticated local client can persistently rewrite Wi-Fi, system, and update settings on an uninitialized Netcore NBR100V2.
The primitive is real, but it requires local reachability during the factory-default or otherwise uninitialized state.
Code / PoCHACKALL/netcore_NBR100V2_V1.3.240614.030928 Router/netcore_nbr100v2_uci_config_tamper.md at main · senxitoyshuyi-ui/HACKALL · GitHub
Wi-Fi routers
A Buffalo WSR-300HP administrator can execute operating-system commands through the management interface.
The added primitive is shell execution, but it already requires administrator credentials; Internet reachability also depends on an optional setting.
ResearchJVNVU#94863997: バッファロー製Wi-Fi製品における複数の脆弱性
What was checked · 4 quiet
Boot chain & TPMQuiet

Supermicro converted a generic AMI BDS/Shell bypass into a broad board map with released, by-request, and unavailable EOL remediation.

Wi-FiQuiet

Netcore added a factory-state persistent configuration path, while Buffalo’s authenticated command injection adds little beyond an existing administrator foothold.

Zero-clickQuiet

No new zero-click packet capability was established; official Android and Qualcomm rendering gaps still leave some component prerequisites unresolved.

Physical accessQuiet

No new physical-access primitive emerged; the relevant change was Supermicro’s product mapping and uneven remediation for an already privileged pre-boot path.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026