Twin pre-auth NetScaler zero-days abused before the patch, a pre-auth F5 OAuth overflow, a CVSS 10.0 Cisco firewall manager, and three Linux kernel bugs on KEV in one week.

CVEasy Weekly

This Week in Exposure

Week 40 · 2026-W40 · September 28 to October 4, 2026

The edge you bought to keep attackers out took the week's worst hits, and none of it needed a login. A NetScaler that terminates your VPN, an F5 that fronts your OAuth logins, and the Cisco appliance that manages your firewall fleet each fell to a single unauthenticated request, and all three are already exploited with a CISA KEV deadline attached. Two of them were being abused before a patch existed to install.

The base scores cluster tight, three of them at 9.5 or above, which is exactly the trap. A queue sorted by CVSS files a VPN gateway next to a lab box and a firewall manager next to a leaf host, when the risk lives in where the appliance sits and what falls with it. Below that, three Linux kernel primitives that turn a foothold into root landed on KEV in one week, and Fire Ant kept tapping the TACACS+ server that watches every administrator log in. Here is the week, ranked by what an attacker actually gets.

Top Exposures This Week

1. Two pre-auth requests that root the NetScaler terminating your VPN

CVE-2026-88771 and CVE-2026-88772 · Citrix NetScaler ADC and Gateway · both CVSS 9.5, unauthenticated · CISA KEV, federal deadline September 30

Citrix broke twice in the same week, both times before authentication. CVE-2026-88771 is an improper input validation flaw (CWE-20) reachable on a code path every NetScaler ADC and Gateway runs, including the default configuration in Citrix's own words. One crafted request and the appliance runs the attacker's command as the NetScaler service. CVE-2026-88772 is a memory overflow reached over DTLS, which listens on UDP port 443 by default on any VPN virtual server unless an operator turned it off, so a crafted DTLS record to that VPN address yields code execution. Neither bug touches the management plane, so a decade of guidance about locking down the management interface with ACLs and jump hosts closes neither one. The fix, CTX697096, shipped September 27; on September 26 vendors and national response teams were telling operators to power the boxes off, because there was nothing to install yet.

Risk read: Both were exploited before the patch shipped, and both are on CISA KEV with a federal remediation deadline of September 30, 2026, one of the few this week that has not already passed. The blast radius is the VPN and AAA edge itself: a rooted Gateway sees session tokens, terminates the tunnel every remote user rides, and sits inside the network it was meant to guard. Exposure is top band on any Gateway, VPN virtual server, or AAA virtual server reachable from the internet, which is the population these devices exist to serve.

Read how both pre-auth paths reach the edge →

2. An OAuth endpoint that hands an attacker root on F5 APM

CVE-2026-94127 · F5 BIG-IP APM OAuth UserInfo handler · CVSS 9.8, unauthenticated, heap overflow · CISA KEV, federal deadline September 25

The vulnerable route is /f5-oauth2/v1/userinfo, the default OpenID Connect endpoint on any BIG-IP APM virtual server that runs an APM access policy plus an OAuth profile and acts as the OAuth Authorization Server. UserInfo answers unauthenticated input by design, since checking the bearer token is the handler's job rather than something in front of it. Public analyses from Rapid7 and Picus Security converge on the same primitive: the handler allocates a fixed heap buffer of 0x4100 bytes for the Authorization header and copies the header in without a length check, the overflow rewrites a callback pointer in a neighboring object, and a return-oriented chain built on that pointer turns the write into code execution. The request lands on the data plane virtual server, the same address a legitimate relying party calls, so management ACLs do not help and Appliance mode does not either, because its constraint is on shell access, not on the OAuth handler.

Risk read: F5 confirmed exploitation in the wild in advisory K000162605 on September 22, and CISA added the CVE to KEV with a federal deadline of September 25, 2026 that has already passed. The uniform 9.8 label hides your estate: on an APM box that only terminates web SSO the vulnerable handler does not exist, and on the box that plays OAuth Authorization Server for a customer identity plane, holding signing keys and fronting federation, that same 9.8 understates it. Exposure is top band wherever an APM virtual server is configured as an OAuth Authorization Server and reachable on its data plane address.

Read how one header overruns the OAuth handler →

3. The Cisco firewall manager answering the internet at CVSS 10.0

CVE-2026-20079 · Cisco Secure Firewall Management Center · CVSS 10.0, exploited in the wild · CISA KEV since September 9

Cisco Secure FMC is the console that pushes policy to a fleet of Firepower Threat Defense firewalls, so a base score cannot tell the FMC answering the internet from the one answering a single jump host, and here the 10.0 is accurate. Cisco published the advisory on March 4, 2026 with no evidence of exploitation, then Cisco PSIRT became aware of in-the-wild abuse in August, Talos confirmed it publicly on September 9, and CISA added the CVE to KEV the same day. VulnCheck cites Censys finding roughly 300 instances publicly exposed and FOFA counting 600 to 700, which is a lot of internet-facing seats for a device that manages other security devices. Cisco tied the observed exploitation to three post-compromise clusters, UAT-12197, UAT-11823, and UAT-11988, which sit inside the target class described in the spotlight below but have not been named as that group.

Risk read: The federal deadline passed on September 12, and the gap between disclosure and confirmed abuse ran about five months, the interval most estates spent leaving a management appliance alone. Blast radius is the point: TRIS scores a manager against the fleet it controls, not as one more host, so a compromised FMC is a control-plane event across every firewall it drives. An FMC whose web interface answers the internet sits in the top band; the same build behind a jump host drops several bands with nothing about the bug changed. Treat any exposed instance that ran through August and September as suspect until a hunt clears it.

Read why the manager scores against its fleet →

4. Three Linux kernel primitives on KEV in one week, all exploited

CVE-2025-39682, CVE-2026-53266, CVE-2025-39964 · Linux kernel kTLS, ebtables SNAT, AF_ALG · CISA KEV under BOD 26-04, three-day deadlines

CISA added all three between September 18 and 22, 2026 with three-day patch deadlines, and Red Hat asserts active exploitation for each. CVE-2025-39682 is a missing per-call type check in kernel TLS: a zero-length record breaks the receive loop before the type registers, a following record of a different type rides the same call through the zero-copy path under assumptions that no longer hold, and Red Hat rates it CVSS 9.8 because it is reachable remotely on any TCP socket with kTLS attached. CVE-2026-53266 is a nonlinear-skb write in the ebtables SNAT target, where an ARP address rewrite can land through skb_store_bits into a splice-imported file page, a Dirty Pipe-class page cache overwrite that Kimmo Suominen mapped to privilege escalation. CVE-2025-39964 is a fourteen-year-old AF_ALG race that STAR Labs demonstrated at Google kernelCTF as privilege escalation and container escape, rated CVSS 7.8.

Risk read: These are the second half of an intrusion, not the front door: they turn any foothold, a web shell, a compromised container, a phished laptop, into root or a container escape, and BOD 26-04 requires forensic triage on assets that could already have been touched, so a patch alone does not close the incident. Exposure follows your kernel builds. The kTLS fix landed in 6.1.149, 6.6.103, 6.12.44 and later, and the priority order tracks reachability: the remotely reachable kTLS bug first, then the two local escalations behind it. A host running an old kernel behind a rooted edge appliance is exactly how this week's items chain.

Read the three primitives and the patch order →

Threat Actor Spotlight

Fire Ant is the China-nexus espionage group Sygnia named in July 2025 for ESXi and vCenter intrusions, with activity that overlaps the UNC3886 cluster Mandiant tracks and no MITRE ATT&CK group ID assigned. In August 2026 Sygnia reported the group moving into the network and management layer, hijacking Cisco IOS XR routers, TACACS+ servers, and Linux management hosts across telecom, critical infrastructure, and defense, motivated by long-term access rather than extortion. The technique worth studying carries no CVE. Sygnia tracks a toolset it calls TacTap: an injector at /usr/sbin/acppid loads a library, /lib/libseconfd.so, into the running tac_plus process, hooks the accept and accept4 calls the daemon uses for new connections, then deletes the library from disk. The tac_plus binary hashes clean the whole time, so file integrity monitoring stays green while the library reads every administrator credential crossing the server in the clear at the moment of use. Sygnia's careful wording is that this specific tac_plus library-injection technique has not been publicly described before, a claim about the record for this daemon, not about process injection in general. Hardening takeaway: two reflexes fail against this at once. File integrity monitoring asks about the disk while the interception lives in memory, and credential rotation crosses the same hook on first use against a tapped server. Watch the process, not the file: alert on unexpected libraries mapped into tac_plus, on injector binaries like acppid, and on collector sockets under /var/run, and treat an exposed TACACS+ server or FMC that ran through August and September as compromised until a live-memory hunt clears it, because this actor edits the log the device writes.

Patch This First

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772. These are the two that were exploited before a patch existed, they are the only KEV items this week whose federal deadline has not passed, September 30, and they root the VPN and AAA edge with no login. Move every NetScaler ADC and Gateway to a fixed build via CTX697096, and remember no configuration setting and no management ACL closes either flaw, since both live on the data path. Because DTLS on UDP port 443 is on by default on VPN virtual servers, an unpatched Gateway was reachable whether or not you use it. Once a build is current, treat any internet-facing Gateway, VPN virtual server, or AAA virtual server as suspect until a hunt clears it, and rotate session secrets and any credentials the appliance held, because a pre-auth root primitive on the edge that ran through this week is a rotate-everything event once it has been reachable.

Signed CVEasy threat-intel IOC bundle current as of 2026-09-28. The desktop app verifies the ED25519 signature before import.

Every top item this week was already exploited, three of the four hold a base score at or above 9.5, and the number could not tell you which box mattered most. The VPN gateway, the OAuth front door, and the firewall manager all rated near the ceiling, yet the one to touch first is the pair still inside an open federal deadline that roots your edge with no login. Ordering that helps is built on your own exposure and on what attackers are doing today, which is the loop our CTEM platform runs with TRIS, and the loop I want this letter to run for you every Monday.

Patch well,
Chris Boker
Founder, CVEasy AI

You are receiving CVEasy Weekly because you subscribed at cveasyai.com.
CVEasy AI · This Week in Exposure · Unsubscribe