Two critical vulnerabilities in authentication gateways landed this week - one already exploited in the wild, the other targeting the SAML processing chain that underpins enterprise single sign-on. When the device brokering your identity assertions is itself the entry point, the identity control plane needs rethinking. Today’s brief also covers a practical AI agent identity playbook derived from nine real incidents, and a state-sponsored campaign proving that push-based MFA is operationally defeated.
In the News
SonicWall SMA1000 CVSS 10 Pre-Auth SSRF Exploited in the Wild
CVE-2026-102255 is a maximum-severity pre-authentication server-side request forgery in SonicWall’s SMA1000 remote-access appliance. The flaw allows unauthenticated attackers to reach internal management functions - no credentials required, no user interaction needed. SonicWall released a patch, and exploitation began three days later.
The timing is the story. Three days between patch availability and active exploitation is now a standard window for critical remote-access flaws. Organizations running SMA1000 appliances that did not patch over the weekend are already inside the exposure window. The pre-authentication nature of this vulnerability means there is no compensating control short of network isolation - if the appliance is internet-facing and unpatched, it is exploitable.
For identity practitioners, this reinforces a structural argument: on-prem remote-access gateways carry their own authentication bypass risk independent of the identity controls layered on top of them. A ZTNA or SSE architecture that brokers access through a cloud-native control plane eliminates this class of pre-auth attack surface entirely.
What defenders should do: Patch SonicWall SMA1000 to the latest firmware immediately. If patching is not possible within hours, remove the appliance from internet-facing exposure. Review access logs for the 3-day window between patch release and your deployment for indicators of unauthorized internal function calls.
Citrix NetScaler SAML RCE - Third Critical CVE in Six Weeks
CVE-2026-107406 is a memory overflow in SAML-configured Citrix NetScaler ADC and NetScaler Gateway appliances. Successful exploitation can lead to remote code execution or denial of service. Only appliances configured as SAML service providers or identity providers are affected - but in enterprise deployments, that is precisely the role NetScaler plays: it is the SAML gateway brokering SSO.
This is the third critical-severity NetScaler CVE in six weeks. That cadence should change the risk calculus for any organization treating NetScaler as a long-term identity infrastructure component. Each patch cycle for a SAML gateway is a window where the authentication control plane itself is vulnerable - and unlike endpoint patches, gateway patches often require maintenance windows that delay deployment.
The SAML processing chain is particularly sensitive because it handles authentication assertions for every application behind the gateway. A compromised SAML gateway does not just grant access to one system - it grants the ability to forge or intercept assertions across the entire SSO trust domain.
What defenders should do: Patch SAML-configured NetScaler ADC and Gateway appliances immediately. Audit SAML trust configurations and assertion validation rules. Begin evaluating cloud-native identity provider alternatives that remove the on-prem SAML gateway as a single point of compromise.
AI Agent Identity Playbook - 6 Controls from 9 Real Incidents
GitGuardian published an analysis of nine real AI agent security incidents spanning May 2025 through July 2026. The consistent finding: in every prompt-injection case, the credential is the target. Attackers do not need to exfiltrate data directly through the agent - they manipulate the agent into using its own credentials in unintended ways, or they extract the credentials themselves for direct use.
The six-control framework is practical and identity-centric. Sandbox execution environments so a compromised agent cannot reach production infrastructure. Scope credentials to the minimum required permissions with short-lived tokens. Lock agent configuration so prompt injection cannot modify tool access. Log every tool call for post-incident reconstruction. Pre-scan the workspace for secrets before the agent accesses it. Deny access by default and require explicit grants for each capability.
These controls limit blast radius but do not prevent prompt injection itself. That distinction matters: organizations deploying AI agents need to treat agent credentials with the same lifecycle governance applied to service accounts and API keys - rotation, least privilege, monitoring for anomalous usage patterns. The agent is a non-human identity, and it needs non-human identity controls.
What defenders should do: Inventory all credentials accessible to AI agents and copilots. Apply least-privilege scoping with short-lived tokens. Implement audit logging for every tool call. Treat agent identity governance as an extension of your NHI program, not a separate initiative.
UAT-11985 APT Bypasses MFA with Real-Time AitM Against Taiwan Researchers
Cisco Talos identified APT group UAT-11985 running spear-phishing campaigns against Taiwanese research organizations. The campaign used AI-generated event invitation lures with highly consistent structure suggesting LLM content generation, delivered via QR code phishing.
The technical payload is an advanced adversary-in-the-middle framework impersonating Google authentication pages. The framework uses hybrid HTTP/WebSocket communication to synchronize the authentication workflow in real time - intercepting credentials and MFA challenges as the user completes them. This is not theoretical MFA bypass research. This is a state-sponsored APT operationally defeating push-based and TOTP-based MFA against real targets.
The only authentication method that defeats this class of attack is phishing-resistant authentication - FIDO2 security keys or platform passkeys that bind the credential to the legitimate origin domain. An AitM proxy cannot relay a FIDO2 assertion because the cryptographic challenge is domain-bound; the phishing domain fails the origin check.
What defenders should do: Deploy phishing-resistant authentication (FIDO2/passkeys) for all users, prioritizing high-value targets such as researchers, executives, and administrators. Monitor for anomalous session characteristics - geographic impossibility, device fingerprint mismatches, WebSocket-based authentication patterns - that indicate proxied authentication attempts.
Defender Action Items
- Patch SonicWall SMA1000 to the latest firmware or isolate from internet exposure immediately - CVE-2026-102255 (CVSS 10.0) is actively exploited
- Patch SAML-configured Citrix NetScaler ADC/Gateway for CVE-2026-107406 (CVSS 9.0) - audit SAML trust configurations and assertion validation
- Inventory AI agent credentials - apply least-privilege scoping, short-lived tokens, and audit logging for every tool call per the GitGuardian six-control framework
- Deploy phishing-resistant authentication (FIDO2/passkeys) - UAT-11985’s real-time AitM campaign demonstrates operational defeat of push-based and TOTP MFA
- Review CISA KEV additions - 5 new CVEs with Oct 11 federal deadline tied to Flax Typhoon disruption
Detection Queries
The following Splunk SPL query identifies anomalous SAML assertion patterns that may indicate exploitation of SAML processing flaws in gateway appliances - specifically oversized assertions or malformed XML that could trigger memory overflow conditions like CVE-2026-107406:
index=netscaler sourcetype="ns:syslog" saml
| eval assertion_size=len(_raw)
| where assertion_size > 8192
| stats count by src_ip, dest_ip, assertion_size, _time
| where count > 3
| sort -assertion_size
This query surfaces SAML-related log entries with unusually large payloads (over 8 KB), which may indicate crafted assertions targeting memory overflow conditions. Tune the threshold based on your environment’s normal SAML assertion sizes. False positive rate is moderate in environments with complex SAML attribute mappings - baseline normal sizes before alerting.
References
- SonicWall SMA1000 CVE-2026-102255 - BleepingComputer
- Citrix NetScaler CVE-2026-107406 - BleepingComputer
- AI Agent Security: Six Controls - GitGuardian Blog
- UAT-11985 AitM Campaign - Cisco Talos
- FBI Disrupts Flax Typhoon Tools - BleepingComputer
- SailPoint AI Velocity Paradox - The Hacker News
- Microsoft PQC TLS Pilot - Microsoft Security Blog
- OpenAI Disrupts Russian/Iranian Ops - The Record
Related Briefs
- NetScaler SAML RCE - CVE-2026-107406 CVSS 9.0
- SonicWall CVSS 10 SSRF - FortiGate 86K Cred Theft
- AI Agents Are Attacking - Identity Governance Gaps Widen
- SonicWall SMA1000 SSRF Hits CVSS 10 - Hotfix Now
- NetScaler SAML Zero-Day CVE-2026-88779 Exploited
Subscribe to The Identity Brief
Get The Identity Brief in your inbox (Mon/Wed/Fri) - Human, machine, and AI identity security — NHI, ITDR, and the IAM market.