Three actively exploited vulnerabilities landed on the CISA Known Exploited Vulnerabilities catalog this week, two of them in the same product. Citrix NetScaler ADC and Gateway deployments running default configurations are exposed to remote code execution with no prerequisite misconfiguration - a worst-case scenario for any appliance that typically sits at the network perimeter handling SSL VPN and application delivery. Meanwhile, ShinyHunters is back with a modified PeopleSoft exploit confirmed by Google, and SharePoint Server joins the KEV list with a deadline of today.
In the News
Two Citrix NetScaler Zero-Days Exploited in Default Configurations
Citrix confirmed active exploitation of two remote code execution vulnerabilities in NetScaler ADC and Gateway: CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772. Both were disclosed and patched on September 27, but exploitation was already underway before patches were available.
CVE-2026-88771 is the more dangerous of the two because it affects default configurations. NetScaler ADC and Gateway appliances do not require any specific misconfiguration or non-standard feature enablement to be vulnerable - if the appliance is running an affected firmware version, it is exploitable. This is the same class of default-config exposure that made CVE-2023-3519 so devastating in 2023, when thousands of NetScaler appliances were compromised before most organizations could patch.
CISA added both CVEs to the Known Exploited Vulnerabilities catalog and set a Wednesday deadline for federal agencies. Citrix’s advisory recommends immediate patching. For organizations that cannot patch within 24 hours, the guidance is straightforward: take the appliance offline until the firmware update can be applied. Given that NetScaler appliances typically sit at the network perimeter handling remote access and application delivery, this is a high-disruption recommendation - but the alternative is running a known-exploited RCE at the edge.
What defenders should do: Apply the September 27 Citrix firmware update immediately. If the patching window exceeds 24 hours, disconnect affected NetScaler ADC and Gateway appliances from the network. Post-patch, review NetScaler access logs and shell histories for indicators of prior compromise during the exploitation window.
ShinyHunters Launches Modified PeopleSoft Extortion Campaign
Google Threat Intelligence confirmed that ShinyHunters has retooled its exploit for CVE-2026-35273 in Oracle PeopleSoft and launched a fresh extortion campaign targeting organizations running PeopleSoft HR and finance modules. ShinyHunters is the same group that made unverified claims about an FBI data breach last week - but the PeopleSoft campaign has independent attribution from Google, giving it concrete credibility.
ShinyHunters has a well-documented pattern: exploit a known vulnerability, exfiltrate data from HR and finance systems, and contact victims with extortion demands. The group’s modification of the CVE-2026-35273 exploit suggests it has adapted to whatever mitigations or detection rules were deployed after the initial disclosure. Organizations running unpatched PeopleSoft instances are at immediate risk - and the data at stake (employee PII, financial records, payroll data) is exactly the type that drives high extortion payments.
What defenders should do: Apply Oracle’s Critical Patch Update for CVE-2026-35273. Segment PeopleSoft application and database tiers to limit lateral movement. Monitor outbound data transfer volumes from database servers for anomalous spikes - ShinyHunters exfiltrates data before making contact, so detection of bulk data movement is the earliest actionable signal.
SharePoint Server CVE-2026-65660 Added to KEV - Deadline Is Today
CISA added Microsoft SharePoint Server vulnerability CVE-2026-65660 to the Known Exploited Vulnerabilities catalog after confirming active exploitation. The federal agency patch deadline is September 28 - today. SharePoint Server remains deeply embedded in enterprise document management, intranet portals, and collaboration workflows, making on-premises deployments high-value targets.
The exploitation of SharePoint vulnerabilities is a recurring pattern. SharePoint Server on-prem instances are frequently the initial access vector because they expose authenticated web services, handle file uploads, and often run with elevated service account privileges. This is exactly the scenario where the gap between cloud-hosted SharePoint Online (patched automatically by Microsoft) and on-prem SharePoint Server (patched manually by the customer) becomes a material security difference.
What defenders should do: Apply the Microsoft security update for CVE-2026-65660 immediately. Audit SharePoint Server ULS logs and Windows Security event logs for exploitation indicators. Evaluate migration timelines for remaining on-prem SharePoint instances - every on-prem deployment is a patching liability that cloud-hosted alternatives eliminate.
JADEPUFFER Destroys Azure Resources via Stolen Service Principals
Microsoft disclosed that the threat actor tracked as Storm-3168 (JADEPUFFER) compromised Azure service principals and conducted an 18-hour destructive campaign in June 2026, systematically deleting cloud resources across targeted tenants. The attack chain is notable because it targeted workload identities - service principals and application registrations - rather than human user accounts.
This matters because most organizations focus their identity monitoring on human accounts: failed logins, impossible travel, MFA challenges. Service principals operate programmatically, authenticate with certificates or secrets rather than passwords, and rarely trigger the same behavioral analytics. JADEPUFFER exploited this blind spot. The 18-hour destructive window - deleting VMs, storage accounts, and databases - suggests the targeted organizations had no automated detection for bulk resource deletion by service principals. This is the MITRE ATT&CK technique T1485 (Data Destruction) executed through T1078.004 (Valid Accounts: Cloud Accounts).
What defenders should do: Audit Azure service principal permissions using the principle of least privilege. Establish behavioral baselines for service principal API calls and alert on resource deletion operations outside normal deployment windows. Ensure cloud backup and disaster recovery procedures cover destructive attacks, not just ransomware encryption.
Defender Action Items
- Citrix NetScaler: Patch to September 27 firmware immediately or take appliances offline. Post-patch, hunt for compromise indicators in shell history and access logs.
- Oracle PeopleSoft: Apply Critical Patch Update for CVE-2026-35273. Segment application tiers. Monitor for anomalous outbound data volumes from database servers.
- Microsoft SharePoint Server: Apply the security update for CVE-2026-65660 today. Audit ULS and Windows Security logs for exploitation artifacts.
- Azure service principals: Audit permissions, establish behavioral baselines for API calls, and alert on bulk resource deletion operations.
- General posture: Three CISA KEV additions in one week - confirm your vulnerability management SLAs can meet the Wednesday and today deadlines.
Detection Queries
SharePoint exploitation often leaves artifacts in Windows Security logs. The following Splunk SPL query detects suspicious process execution originating from SharePoint’s w3wp.exe worker process - a common indicator of successful exploitation leading to command execution:
index=windows sourcetype=WinEventLog:Security EventCode=4688
Creator_Process_Name="*\\w3wp.exe"
New_Process_Name!="*\\csc.exe" New_Process_Name!="*\\conhost.exe"
| eval suspect_proc=case(
match(New_Process_Name, "(?i)(cmd|powershell|certutil|bitsadmin|mshta|wscript|cscript)"), "high",
match(New_Process_Name, "(?i)(net|whoami|nltest|dsquery|ipconfig|systeminfo)"), "recon",
1=1, "low"
)
| where suspect_proc IN ("high", "recon")
| stats count by _time, host, Creator_Process_Name, New_Process_Name, suspect_proc
| sort - _time
This query filters out expected child processes of the IIS worker (like the C# compiler csc.exe) and flags command interpreters and reconnaissance utilities spawned by the SharePoint application pool. False positive rate is low in environments where SharePoint Server does not legitimately spawn cmd.exe or PowerShell - which should be most environments.
Related Briefs
- AI Agent Accessed a Government Portal - Was It Open?
- Roundcube Pre-Auth SQLi CVE-2026-48842 Exploited
- Check Point VPN Zero-Day - CVE-2026-85102 Pre-Auth RCE
- F5 BIG-IP APM OAuth Zero-Day - CVE-2026-94127
- F5 BIG-IP APM Zero-Day RCE - CVE-2026-94127
References
- Citrix NetScaler zero-day advisory - BleepingComputer
- ShinyHunters PeopleSoft campaign - SecurityWeek
- SharePoint CVE-2026-65660 exploitation - SecurityWeek
- JADEPUFFER Azure destructive campaign - The Hacker News
- DC Health Benefit Exchange data exposure - SecurityWeek
- Nvidia AI agent safety platform - SecurityWeek
- Cloudflare Containers cross-tenant flaw - BleepingComputer
Subscribe to it-learn Brief
Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.