Security Weekly #Sep 28, 2026: Citrix NetScaler 0-day, Arista VeloCloud, WordPress Core, Microsoft SharePoint and MikroTik RouterOS

Cybersecurity weekly cover — critical CVEs for VMware vCenter, TeamCity, Fortinet and Palo Alto, Aug 25 2026

The final week of September proved unusually volatile across edge networking appliances and foundational infrastructure services. Over the weekend, Citrix prompted the largest disruption following the technical disclosure of two actively exploited zero-day flaws in NetScaler ADC and Gateway appliances that attackers weaponized prior to patch availability. Concurrently, CISA added a CVSS 10.0 unauthenticated compromise in Arista VeloCloud SD-WAN Orchestrator to the KEV catalog, alongside a notable Path Traversal issue in WordPress Core itself. If you manage perimeter gateways, VPN endpoints, or enterprise web servers, here is what demands immediate verification this Monday morning.


1. Citrix NetScaler ADC & Gateway: Dual In-The-Wild Zero-Day RCE Flaws (CVE-2026-88771 & CVE-2026-88772)

Late last week, security researchers at watchTowr disclosed the discovery of two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway during post-incident forensic investigations. Both flaws were actively leveraged in the wild to achieve unauthenticated remote code execution (RCE) on internet-exposed appliances. The severity led several organizations to proactively sever appliance internet connectivity prior to vendor confirmation.

On Sunday, September 27, Citrix officially confirmed the campaign and issued emergency software releases. The first flaw (CVE-2026-88771) stems from improper input validation, while the second (CVE-2026-88772) involves memory buffer manipulation errors. Both carry a critical CVSS 9.5 rating and were promptly added to CISA KEV. Because active exploitation preceded patch availability, upgrading alone is insufficient — administrators must perform forensic log audits and filesystem reviews against published indicators of compromise (IoCs).

  • Identifiers: CVE-2026-88771, CVE-2026-88772
  • Base Score: CVSS 9.5 (Critical)
  • Exploitation Status: Active in-the-wild zero-day exploitation (added to CISA KEV on Sept 27)
  • Affected Systems: NetScaler ADC and NetScaler Gateway builds prior to 14.1-73.37 and 13.1-64.23 (including FIPS releases)
  • Mitigation: Deploy builds 14.1-73.37 / 13.1-64.23 immediately, conduct post-incident forensics and IoC analysis
  • Source: Citrix Security Bulletin (CTX697096)

2. Arista VeloCloud Orchestrator: Unauthenticated SD-WAN Takeover (CVE-2026-93952)

A severe incident also struck the corporate SD-WAN networking layer. Arista VeloCloud Orchestrator (VCO, formerly VMware SD-WAN Orchestrator) carries a critical CVSS 10.0 vulnerability. The flaw resides in improper input validation logic in on-premise deployments where edge appliance (VeloCloud Edge) certificate-based authentication is enabled.

An unauthenticated remote attacker with network access to the VCO web portal and a public certificate component can invoke privileged backend methods, gaining administrative control over the orchestration server. Consequently, this provides full access to all managed downstream Edge network nodes. Active exploitation is confirmed and listed in CISA KEV. Arista published patches for the 5.2 and 6.4 release branches. The advisory details specific attacker artifacts, including files at /usr/local/sbin/.vcnode.js and the vc-sysmon.service systemd unit.

  • Identifier: CVE-2026-93952
  • Base Score: CVSS 10.0 (Critical)
  • Exploitation Status: Confirmed active in-the-wild exploitation (CISA KEV, Sept 22)
  • Affected Systems: VeloCloud Orchestrator on-premise 5.2 (up to 5.2.3.15), 6.4 (up to 6.4.2.7), 6.1 (up to 6.1.3.7), and 7.0 (up to 7.0.0.2)
  • Mitigation: Upgrade to version 5.2.3.16 / 6.4.2.8 or newer, restrict web ingress, and audit running system processes
  • Source: Arista Security Advisory 0183

3. WordPress Core: Path Traversal Flaw in Page Template Handling (CVE-2026-87902)

The WordPress security team rolled out a multi-branch security release spanning supported branches from 4.7 up to 7.1. Tracked as CVE-2026-87902, the vulnerability involves a Path Traversal defect in the get_page_template() function responsible for resolving template hierarchy.

An unauthenticated remote attacker sending crafted HTTP requests can force the rendering engine to include and execute arbitrary local .php files situated outside active theme directories. If a malicious PHP payload was previously introduced through a third-party plugin vulnerability or upload defect, this flaw provides direct remote code execution. Added to CISA KEV on September 25, administrators should verify that automatic minor updates completed successfully across production installations.

  • Identifier: CVE-2026-87902 (GHSA-7hp8-65ch-5whp)
  • Base Score: CVSS 8.1 (High)
  • Exploitation Status: Added to CISA KEV on September 25, 2026
  • Affected Systems: WordPress Core branches 4.7 through 7.1
  • Mitigation: Upgrade to patched versions (7.1.2, 7.0.6, 6.7.9, 6.6.9, 6.5.12, 6.4.12, etc.)
  • Source: WordPress Security Advisory (GHSA-7hp8-65ch-5whp)

4. Microsoft SharePoint Server: ToolPane Injection to Memory-Only Webshell (CVE-2026-65660)

CISA cataloged CVE-2026-65660 impacting Microsoft SharePoint Server. While originally designated by Microsoft as moderate spoofing, in-depth technical analysis published by Viettel Cyber Security researchers confirmed that the flaw yields full remote code execution within the application server context.

The issue resides in the ToolPane web-part processing component, which reconstructs Register directives without sanitizing quote characters. An authenticated attacker can inject directives registering arbitrary .NET classes, bypassing the native SafeControls filter. Subsequent execution via XamlServices.Parse() triggers insecure deserialization and spawns a fileless memory-resident webshell. Microsoft released security updates that eliminate the flaw and disable vulnerable handling by default.

  • Identifier: CVE-2026-65660
  • Base Score: CVSS 8.8 (High)
  • Exploitation Status: Confirmed in-the-wild exploitation, public PoC available, added to CISA KEV on Sept 25
  • Affected Systems: Microsoft SharePoint Server 2016, 2019, and Subscription Edition
  • Mitigation: Install cumulative Microsoft SharePoint security updates
  • Source: Microsoft Security Response Center (CVE-2026-65660)

5. MikroTik RouterOS: SSH Session Authentication Logic Bypass (CVE-2026-67279)

MikroTik RouterOS was subject to another SSH protocol handling vulnerability. Tracked as CVE-2026-67279 and added to CISA KEV on September 25, the flaw occurs when the SSH daemon improperly transitions into the authenticated session phase upon receiving a key re-negotiation (re-key) request, even if initial user authentication was incomplete or unverified.

This allows an unauthenticated client to establish an interactive session channel and execute router commands. MikroTik addressed the issue in recent RouterOS v7 releases. For homelab and enterprise administrators, this serves as another reminder of baseline security hygiene: management interfaces and SSH ports should never remain reachable from public WAN interfaces and must be restricted to dedicated management subnets or secure WireGuard/IPsec tunnels.

  • Identifier: CVE-2026-67279
  • Base Score: CVSS 6.5 (Medium)
  • Exploitation Status: Added to CISA KEV catalog on September 25, 2026
  • Affected Systems: MikroTik routers running RouterOS v7
  • Mitigation: Upgrade RouterOS to current stable builds and disable SSH access (TCP 22) on WAN interfaces
  • Source: MikroTik Security Advisory

Action Items for Today

  1. Audit and Patch Citrix NetScaler Gateways: Deploy builds 14.1-73.37 or 13.1-64.23 immediately and examine logs for indicators of pre-patch compromise (CVE-2026-88771 / CVE-2026-88772).
  2. Update Arista VeloCloud Orchestrator: Upgrade on-premise deployments to 5.2.3.16 / 6.4.2.8+ and verify that SD-WAN web management interfaces are not exposed publicly.
  3. Verify WordPress Core Release Levels: Confirm that WordPress instances completed automatic minor updates to secure releases (such as 7.1.2, 7.0.6, 6.7.9, etc.) to remediate CVE-2026-87902.
  4. Patch Microsoft SharePoint Servers: Apply current cumulative security updates to mitigate ToolPane injection vulnerabilities (CVE-2026-65660).
  5. Isolate WAN SSH on MikroTik Routers: Ensure RouterOS is up to date and verify firewall filter rules drop all inbound SSH connection attempts on public interfaces.