National CERT advisories warned organizations to urgently patch critical vulnerabilities in Citrix NetScaler ADC/Gateway, Zyxel GS1900 switches, Froxlor hosting panels, and D-Link products. CIRT.cm said CVE-2026-88771, CVE-2026-88772 affecting Citrix and CVE-2026-7273 affecting Zyxel were listed by CISA as actively exploited. Citrix released fixes for eight NetScaler flaws, CVE-2026-88771 through CVE-2026-88778; affected standard deployments should update to 13.1-64.23 or 14.1-73.37, with separate fixed releases for FIPS/NDcPP builds.
GreyNoise reportedly identified 996 compromised Zyxel GS1900 devices in 48 countries exploiting unauthenticated LAN-side stack overflow CVE-2026-7273 for OS command execution, configuration and credential-hash theft. Separately, Froxlor fixed three severe authenticated privilege-boundary flaws in version 2.3.12: CVE-2026-100716 and CVE-2026-100717 (CVSS 9.9), plus CVE-2026-100715 (CVSS 9.6), which can enable root-level operations or breach shared-hosting isolation. Organizations should patch immediately, identify exposed management interfaces, enforce MFA and non-default credentials, restrict administrative access, and investigate unusual cron activity, generated web-server configurations, and signs of device compromise.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
CIRT.cm issued alert CIRT-AL-2026-09-28 to Cameroonian organizations covering critical Citrix, Zyxel, Froxlor, and D-Link vulnerabilities. It said CISA listed Citrix CVE-2026-88771 and CVE-2026-88772, as well as CVE-2026-7273, as actively exploited and urged immediate remediation.
Froxlor disclosed CVE-2026-100715, CVE-2026-100716, and CVE-2026-100717, affecting version 2.3.10 and earlier. The flaws permit low-privileged authenticated customers to abuse root-run cron operations or inject web-server directives, potentially compromising shared-hosting isolation.
Around August 17, 2026, an unidentified Chinese-speaking actor actively exploited CVE-2026-7273 against Zyxel GS1900 switches. GreyNoise reported 996 compromised devices in 48 countries, with attackers stealing device configurations, network information, and hashed root credentials.
Zyxel released firmware updates in June 2026 to address CVE-2026-7273, a LAN-reachable unauthenticated stack-based buffer overflow in GS1900 Smart Managed Switch firmware that can enable operating-system command execution.
Arctic Wolf reported active exploitation of CVE-2026-32996, a local privilege-escalation vulnerability in Veeam Agent for Microsoft Windows. Veeam fixed the issue in Veeam Backup & Replication 13.0.2.29 and Veeam Agent for Windows build 13.0.3.1220.
GreyNoise linked the actor exploiting Zyxel GS1900 devices to campaigns exploiting the WP2Shell WordPress chain and CVE-2026-60004 in Gitea. The reported WordPress campaign compromised 49 organizations in 29 countries and stole credentials and SQL databases, while the Gitea activity enabled source-code and credential theft.
CISA added the Zyxel GS1900 vulnerability CVE-2026-7273 to its Known Exploited Vulnerabilities catalog and set September 24, 2026, as the remediation deadline.
Citrix released security updates for CVE-2026-88771 through CVE-2026-88778 in NetScaler ADC and NetScaler Gateway. Fixed releases include 13.1-64.23, 14.1-73.37, 13.1-37.279 for ADC FIPS/NDcPP, and 14.1-73.37 FIPS for ADC FIPS deployments.
Froxlor released version 2.3.12 to remediate CVE-2026-100715, CVE-2026-100716, and CVE-2026-100717. No public exploit was reported as of the disclosure's publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcecirt.cm
Open sourcecyberveille.ch
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.