The Week in Short
This week was dominated by internet-facing control-plane flaws: three actively exploited Citrix NetScaler vulnerabilities in rapid succession, a critical FortiMail path-traversal zero-day added to CISA KEV, and a Cisco SD-WAN Manager authentication bypass under active attack. New high-severity issues also affected GitLab AI Gateway, Rejetto HFS, Atlassian Data Center, Microsoft Exchange, LibreOffice/OpenOffice, and Dell CSM, alongside AI-agent and MCP ecosystem risks. Attackers turned edge appliances, email gateways, workflow engines, and AI infrastructure into practical paths to denial-of-service, remote code execution, mailbox access, and identity compromise. The most urgent work is to patch internet-facing control planes, validate exploitation, rotate connected credentials, and constrain autonomous tooling and agent environments.
Key Takeaways
- Citrix NetScaler faced three security issues during the week: CVE-2026-88771 and CVE-2026-88772 were actively exploited RCE vulnerabilities, while CVE-2026-88779 was an actively exploited SAML-related DoS vulnerability.
- FortiMail CVE-2026-104286 and Cisco SD-WAN Manager CVE-2026-76504 were added to CISA KEV during the reporting window following reports of active exploitation.
- GitLab AI Gateway CVE-2026-90970 (CVSS 9.9) can allow authenticated users with Duo Agent Platform access to execute commands on self-hosted gateways under certain conditions.
- Rejetto HFS CVE-2026-61500, originally published in July, was confirmed as exploited on October 5, 2026; the flaw enables administrator session forgery and remote code execution through a predictable signing key.
- Atlassian Data Center CVE-2026-21589 permits unauthenticated reading of known files in eight products; cloud instances are patched, self-hosted must be upgraded.
- AI-agent and supply-chain risks included Wikimedia-reported OpenAI agent activity, MCP marketplace governance gaps, and Glow’s PixelLeak screenshot exposure on GitHub.
Critical CVEs Actively Exploited
New Incidents and Disclosures
Deep Dives: The Incidents That Matter
Citrix NetScaler: three exploited flaws
Citrix published a security bulletin on September 27 covering CVE-2026-88771 and CVE-2026-88772, both critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an unauthenticated remote code execution flaw, while CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service. Citrix confirmed that exploitation of both vulnerabilities had been observed on unmitigated NetScaler deployments. [Citrix security bulletin for CVE-2026-88771 and CVE-2026-88772]
On October 3, Citrix disclosed CVE-2026-88779, a memory-overflow vulnerability that can cause denial of service when NetScaler is configured as a SAML service provider (SP) or identity provider (IdP). The vulnerability carries a CVSS 4.0 score of 8.7 and was added to CISA’s Known Exploited Vulnerabilities catalog on October 4. [Citrix security bulletin for CVE-2026-88779]
Action: Inventory every internet-facing NetScaler instance; apply the fixed builds for all three CVEs; remove direct management exposure; review SAML configuration; inspect authentication and outbound traffic; and rotate credentials accessible from affected appliances.
FortiMail and Cisco SD-WAN: active exploitation
Fortinet disclosed CVE-2026-104286, a FortiMail path traversal and NULL-byte flaw allowing unauthenticated arbitrary file writes. CISA added it to KEV. Cisco disclosed CVE-2026-76504, a URI-encoding authentication bypass in Catalyst SD-WAN Manager that grants admin API access without credentials; exploitation was confirmed and it was also added to KEV.
Action: Patch both products immediately; isolate management interfaces; review HTTP/API logs, configuration changes, and policy pushes; and rotate credentials and tokens connected to these systems.
GitLab AI Gateway: command execution
GitLab disclosed CVE-2026-90970 on October 2. Under certain conditions, an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox and execute commands on a self-hosted AI Gateway. GitLab-hosted gateways were already remediated; self-managed organizations must update to fixed gateway versions.
Rejetto HFS: predictable session key enables admin access and RCE
CVE-2026-61500 affects Rejetto HFS versions 3.0.0 through 3.2.0. The vulnerability stems from the use of the non-cryptographic Math.random() function to generate the session-cookie signing key. Because the server exposes enough generator output during unauthenticated login responses, a remote attacker can reconstruct the generator state and recover the signing key.
With the key, an attacker can forge a valid administrator session cookie, gain administrative access, and execute commands through the server_code configuration feature. Upgrade to HFS 3.2.1 or later, rotate administrator credentials, and investigate exposed HFS servers for signs of compromise.
AI Security Watch
AI-agent risk this week centered on execution boundaries, tool access, and ecosystem governance. Wikimedia reported unauthorized OpenAI agent activity, including test edits, citation-tool probing, unsuccessful Etherpad compromise attempts, and heavy automated traffic. OX Security’s review of 15,465 public MCP servers found a lack of marketplace vetting, expired domains, and consumer-tunnel routing.Glow’s PixelLeak research reported that AI coding agents had published more than 13,000 internal screenshots from hundreds of organizations to public GitHub repositories.
- Allowlist tools, APIs, domains, and repository sources for AI agents.
- Use short-lived, narrowly scoped credentials and read-only access by default.
- Require approval for state-changing, external-communication, and data-export actions.
- Capture prompts, tool calls, returned data, commands, filesystem access, and egress.
- Separate browsing, code execution, production deployment, and sensitive-data environments.
Detection Ideas
What to Do This Week
- Patch exposed Citrix NetScaler, FortiMail, Cisco SD-WAN Manager, GitLab AI Gateway, Rejetto HFS, Atlassian Data Center, Microsoft Exchange, LibreOffice, and Dell CSM assets.
- Validate compromise before and after patching; a fixed version does not prove that an intrusion did not occur.
- Rotate application, API, OAuth, CI/CD, package, model-provider, and storage credentials connected to exposed systems.
- Remove direct public access to management planes; require MFA, VPN/zero trust, and device posture controls.
- Inventory MCP servers and AI plugins; restrict to approved registries and monitor prompts, tool calls, and egress.
How Unified WAAP Protection Helps
This week’s incidents show why WAAP must extend beyond static HTTP signatures. Risk moved through edge devices, email gateways, identity APIs, AI gateways, MCP servers, and third-party integrations.
- Virtual patching for traversal, authentication bypass, malicious request patterns, and anomalous API behavior.
- Continuous discovery of exposed APIs, management interfaces, AI-gateway routes, workflow endpoints, and third-party integrations.
- Behavioral bot detection for exploit scanning, credential stuffing, automated extraction, and API abuse.
- Unified L3/L4/L7 telemetry linking edge anomalies with API, identity, application, and cloud-control-plane events.
Frequently Asked Questions (FAQ)
1. What is the most urgent issue this week?
Prioritize Citrix NetScaler, FortiMail, Cisco SD-WAN Manager, GitLab AI Gateway, Rejetto HFS, and public-facing Atlassian Data Center installations. These systems are edge, management, identity, email, or application-control planes.
2. Were the NetScaler flaws exploited in the wild?
Yes. Reporting during this window described active exploitation of CVE-2026-88771 and CVE-2026-88772, plus targeted zero-day attacks for CVE-2026-88779.
3. Is GitLab AI Gateway CVE-2026-90970 unconditional RCE?
No. It requires an authenticated user with Duo Agent Platform access and certain flow configurations on a self-hosted AI Gateway. GitLab-hosted gateways were already remediated.
4. How should AI agents be treated from a security perspective?
As privileged automation identities: scoped tools, read-only access by default, approval gates for high-impact actions, strict egress controls, rate limits, anomaly detection, and complete tool-call telemetry.