Cyber Roundup: Week of September 21
Tabla de contenido
- 1. Citrix: CVE-2026-88771 and CVE-2026-88772 NetScaler zero-days exploited before patches existed
- 2. Check Point: CVE-2026-93616 management server zero-day exploited quietly since July
- 3. Microsoft: SharePoint CVE-2026-65660 reclassified from spoofing to RCE after six weeks of exposure
- 4. F5: BIG-IP APM CVE-2026-94127 exploited as zero-day before the September 9 fix
- 5. ReversingLabs: tw-pkgprobe-7731 malicious npm package harvested Twilio developer credentials
- El patrón en las cinco historias
Aquí están las noticias principales que te perdiste la semana pasada.
1. Citrix: CVE-2026-88771 and CVE-2026-88772 NetScaler zero-days exploited before patches existed
El titular: On September 26, 2026, watchTowr publicly warned that two previously unknown remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway were being exploited in the wild, based on forensic investigations at multiple compromised organizations. Citrix confirmed both flaws the following day, September 27, and published bulletin CTX697096 with patches for CVE-2026-88771 (CVSS 9.5, improper input validation) and CVE-2026-88772 (CVSS 9.5, memory overflow via DTLS). CISA added both to the KEV catalog the same day.
Lo que realmente estamos viendo: Public warning came before vendor confirmation, before CVE assignment, and before any patch existed. Organizations that waited for a Citrix advisory before acting lost days of response time to organizations that acted on watchTowr’s warning.
CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, including default configurations. CVE-2026-88772 requires DTLS to be enabled, which is the default on VPN virtual servers. Active exploitation began before Citrix was aware of the vulnerabilities, and forensic artifacts recovered from compromised appliances include reverse-shell backdoors appended to rc.netscaler for persistence across reboots. There is no workaround for either flaw; the only mitigation is upgrading to the fixed builds. Kevin Beaumont independently confirmed active exploitation on September 26, and the Dutch National Cyber Security Centre sent private notifications to affected Dutch organizations before public disclosure.
La pregunta del CISO: When credible researchers warn about an unpatched flaw in an appliance you operate, can your team take that appliance offline within hours, or does the response require a CVE and a vendor advisory that may not arrive for days?
2. Check Point: CVE-2026-93616 management server zero-day exploited quietly since July
El titular: On September 22, 2026, Check Point published an emergency advisory for CVE-2026-93616, a CVSS 9.8 pre-authentication directory traversal in the Security Management Server that allows an unauthenticated attacker to upload and execute scripts. The company confirmed the flaw was exploited against a handful of customers in targeted attacks observed on July 23, two months before the advisory. Separately, Check Point warned that CVE-2026-85102, a CVSS 9.8 certificate validation flaw in Security Gateway VPN patched on September 9, had been under active exploitation against Spark firewall customers since September 12. CISA added both to KEV on September 22 with a federal deadline of September 25.
Lo que realmente estamos viendo: The management server flaw sat unpatched for two months while an unknown actor used it selectively. The VPN flaw had a fix available for three days before mass exploitation began. Both patterns are the standard playbook now, not the exception.
CVE-2026-93616 affects Security Management Server, Multi-Domain Security Management, Log Server, and SmartEvent. Compromise of the management tier grants administrative control over the firewall policies that govern every downstream gateway, which is a categorically different blast radius from a compromised gateway itself. Check Point described the July 23 detection as “a handful of pinpointed exploitation events” rather than a broad campaign, which typically indicates a targeted actor. Attribution has not been disclosed.
La pregunta del CISO: If your Check Point management server was compromised in late July, would your logs still contain enough evidence to reconstruct what the attacker did, or has that data already rolled off retention?
3. Microsoft: SharePoint CVE-2026-65660 reclassified from spoofing to RCE after six weeks of exposure
El titular: On September 25, 2026, CISA added CVE-2026-65660 to the KEV catalog with a federal patching deadline of September 28. The flaw is a code injection vulnerability in Microsoft SharePoint that allows an authenticated attacker with low-level access to execute code without user interaction. Microsoft originally shipped the fix on August 11 as part of Patch Tuesday and classified the flaw as a spoofing issue. The National Vulnerability Database assigned it a CVSS score of 8.8, two full points above Microsoft’s original 6.5 rating. Early-warning platform Previdian reported exploitation attempts starting September 24 and web shell deployment on September 25.
Lo que realmente estamos viendo: A six-week gap between vendor patch and CISA KEV listing is the window that matters most operationally. During that window, the fix existed and the urgency signal did not. Organizations that patched based on CVSS ratings rather than exploitability signals were exposed for the full six weeks.
Microsoft’s classification of the flaw as “spoofing” rather than remote code execution meant it landed in most enterprise patching queues at the priority level Microsoft’s rating implied, not the priority level the flaw actually warranted. Exploitation began shortly after Viettel Security, the researchers who reported it, disclosed technical details publicly. CISA’s KEV catalog now contains 16 SharePoint vulnerabilities, eight of them discovered and patched in 2026 alone.
La pregunta del CISO: How does your patching program weigh vendor severity ratings against independent scoring, and when NVD assigns a two-point higher score than the vendor did, does that trigger a re-prioritization or a footnote?
4. F5: BIG-IP APM CVE-2026-94127 exploited as zero-day before the September 9 fix
El titular: On September 22, 2026, CISA added CVE-2026-94127 to the KEV catalog. The vulnerability is a CVSS 9.8 heap-based buffer overflow in F5 BIG-IP Access Policy Manager that allows an unauthenticated attacker to execute code remotely against internet-facing management planes. The flaw affects BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0 when the access policy uses an OAuth authorization server profile. F5 shipped engineering hotfixes and an iRule mitigation with the September 9 disclosure, and the vulnerability was exploited as a zero-day before the fix existed.
Lo que realmente estamos viendo: F5 is the third named perimeter access-management vendor added to KEV in a two-week window, alongside Check Point Gateway and Citrix NetScaler in this same roundup. Perimeter identity infrastructure is under coordinated attention from multiple actors, not one.
The OAuth authorization server profile requirement narrows the affected population significantly, but the deployments that meet the criteria are typically the ones with the highest-value session traffic to protect. BIG-IP APM enforces access decisions between external users and internal enterprise applications, so a compromised APM instance produces both credential theft and direct network access. The 13-day gap between F5’s September 9 patch and the KEV listing on September 22 reflects the standard pattern for post-patch exploitation.
La pregunta del CISO: Which of your BIG-IP APM policies use OAuth authorization server profiles, and if that inventory does not exist, how quickly can your F5 team produce one that security can trust?
5. ReversingLabs: tw-pkgprobe-7731 malicious npm package harvested Twilio developer credentials
El titular: On September 22, 2026, ReversingLabs researcher Lucija Valentić disclosed a malicious npm package named tw-pkgprobe-7731 that masqueraded as an authorized Twilio HackerOne bug-bounty probe while harvesting environment variables, Twilio account SIDs, and AUTH_TOKEN credentials from developer machines. The package was uploaded in mid-August 2026 by an npm account named twdepprobe7731 and published 11 successive versions in a 45-minute window on the same day. Each version refined the credential-harvesting capability. The npm user account was removed before disclosure.
Lo que realmente estamos viendo: The package explicitly checked whether it was running inside a Twilio developer environment and immediately exited if not. Non-targeted machines saw nothing. The malware exhibited targeted-actor discipline against a specific vendor ecosystem, not opportunistic scanning.
Comments inside the package described it as an “Authorized bug-bounty research probe” for the Twilio HackerOne program. The code claimed to run only inside Twilio’s serverless packager sandbox and to collect local host context without destructive action. The framing was designed to survive superficial code review during a bug bounty submission or dependency audit. Later versions searched for folders named after specific Twilio account SIDs and injected a custom npm proof-of-concept package into node_modules when a match was found. Version 1.0.4 introduced explicit exfiltration of process.env.ACCOUNT_SID and process.env.AUTH_TOKEN, which is credential material sufficient to compromise the victim’s entire Twilio account.
La pregunta del CISO: Do your developer workstations block outbound webhook traffic from unknown npm packages by default, or does the trust boundary between a developer’s laptop and the open internet still assume that every dependency in package.json is what it says it is?
El patrón en las cinco historias
Every one of these stories was live for days or weeks before the vendor said so. If your response timeline starts at the advisory, your response timeline is already too late.
