Executive Summary
The final week of September 2026 closed with fresh evidence that both opportunistic exploitation and state-sponsored campaigns continued to accelerate, as critical zero-day vulnerabilities in network perimeter infrastructure drew emergency responses from vendors, national CERTs, and law enforcement, while previously reported exploit chains saw continued weaponization by additional threat actors.
CISA added six vulnerabilities to the Known Exploited Vulnerabilities catalog, headlined by two Citrix NetScaler ADC and Gateway remote code execution flaws exploited as zero-days before Citrix released patches, with the Dutch NCSC-NL, law enforcement, and national CERTs privately warning organizations to shut down appliances ahead of public disclosure. The remaining additions included a Microsoft SharePoint code injection flaw patched in August that chained with an authentication bypass for pre-authentication RCE, a MikroTik RouterOS SSH rekeying flaw exploited as part of the MikroTrick takeover chain, an Apple CoreGraphics out-of-bounds write used in targeted attacks described as extremely sophisticated, and a WordPress Core remote file inclusion vulnerability that drew over 548,000 exploitation attempts within 24 hours of disclosure.
Continuing from last week's coverage of UTA0560 and JungleBamboo exploiting chained Chrome and Windows zero-days, Volexity identified UTA0565 as the third Chinese APT group to weaponize the same shared exploit kit, deploying phishing campaigns through typosquatted media and NGO websites to deliver a previously undocumented backdoor tracked as CLEANGULP. The continued emergence of independent operators reinforced Volexity's assessment of coordinated sharing within the Chinese computer network exploitation community.
Key highlights of the week:
- CISA added six vulnerabilities to the KEV catalog.
- Two Citrix NetScaler zero-days drew emergency pre-disclosure warnings from the Dutch NCSC-NL and law enforcement before patches existed.
- Active exploitation of SharePoint and MikroTik RouterOS flaws escalated to webshell deployment and persistent backdoor creation.
- Volexity linked a third Chinese APT group, UTA0565, to the shared Chrome and Windows zero-day chain reported last week.
What are the top trending or critical vulnerabilities observed this week?
Several high-impact vulnerabilities are currently trending across the cybersecurity community, demanding immediate attention and patch prioritization. Monitoring these emerging and widely discussed threats provides valuable insights, enabling organizations to make informed security decisions and strengthen their overall defense posture.
CVE-2026-65660 - Code Injection vulnerability in Microsoft SharePoint
A Code Injection vulnerability in Microsoft SharePoint Server allowed an authenticated attacker with low-level access to execute code over a network without user interaction, affecting SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. VCSLab identified the flaw as a SafeControls bypass in the EditingPageParser type-check mechanism that, when chained with an authentication bypass in ToolPanePage, elevated the vulnerability from authenticated code injection to pre-authentication remote code execution with in-memory webshell deployment across all SharePoint versions including 2013. Microsoft addressed the vulnerability in the August 2026 Patch Tuesday release by disabling the vulnerable ToolPane.GetPartPreviewAndPropertiesFromMarkup() function by default. A public proof-of-concept was available, and CISA added CVE-2026-65660 to the KEV catalog.
CVE-2026-67279 - Improper Enforcement of Behavioral Workflow vulnerability in Mikrotik RouterOS
An Improper Enforcement of Behavioral Workflow vulnerability in MikroTik RouterOS allowed an unauthenticated client to bypass SSH authentication by initiating a key renegotiation, advancing the connection into the post-authentication protocol phase without credentials and enabling the client to open a session channel and submit execution requests. The vulnerability chained with CVE-2026-86060 to achieve full unauthenticated administrative takeover, and affected RouterOS 6.x prior to 6.49.21, 7.x Long-term prior to 7.23.4, and 7.x Stable prior to 7.24.2. CERT Polska confirmed active exploitation in the wild, and Bishop Fox reproduced the full chain and published a detailed technical analysis, discovering real-world compromise artifacts including persistent backdoor accounts and scheduled re-creation scripts on internet-facing devices. With a public proof-of-concept circulating and active exploitation confirmed, CISA added this vulnerability to the KEV catalog.
CVE-2026-86950 - Out-of-Bounds Write vulnerability in Apple Multiple Products
An Out-of-Bounds Write vulnerability in the CoreGraphics component of Apple iOS, iPadOS, and macOS allowed an attacker to achieve arbitrary code execution by processing a maliciously crafted file, affecting iOS and iPadOS versions prior to 26.7.1 and macOS versions prior to Sequoia 15.8.1 and Tahoe 26.7.1. Apple acknowledged that the flaw may have been exploited in what the company described as an "extremely sophisticated attack against specific targeted individuals" running iOS versions prior to iOS 27. Meta Product Security discovered and reported the vulnerability, while Apple disclosed neither the number of targeted individuals, the success of exploitation attempts, nor attribution to any threat actor or campaign. Apple addressed the vulnerability with improved bounds checking across all affected platforms, and CVE-2026-86950 was subsequently cataloged under CISA's KEV catalog.
CVE-2026-88771 - Improper Input Validation vulnerability in Citrix NetScaler
An Improper Input Validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway allowed an unauthenticated attacker to execute arbitrary commands on any affected deployment running default configurations, without requiring any additional feature enablement. The flaw affected NetScaler ADC and Gateway versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS. Citrix discovered the vulnerability while investigating incidents in customer environments and confirmed active zero-day exploitation at multiple organizations worldwide prior to patch availability. The Dutch NCSC-NL issued a pre-notification based on intelligence from a European partner CERT, and watchTowr independently verified active exploitation one day before Citrix released security bulletin CTX697096 on September 27, 2026. The identity of the threat actors, the number of compromised organizations, and the exploitation methodology remained undisclosed, and CISA added CVE-2026-88771 to the KEV catalog.
CVE-2026-88772 - Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix NetScaler
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway allowed a remote attacker to achieve code execution or denial of service when DTLS was enabled, a default setting on VPN virtual servers. The flaw affected NetScaler ADC and Gateway versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS. The Dutch NCSC-NL pre-notification indicated that one of the two disclosed Citrix zero-days allowed attackers to place shellcode directly into memory, while technical details on the second remained under investigation. Citrix discovered CVE-2026-88772 alongside CVE-2026-88771 while investigating incidents in customer environments, confirmed active zero-day exploitation of both flaws, and released fixes in security bulletin CTX697096 on September 27, 2026. Given the confirmed zero-day exploitation and absence of any workaround, CVE-2026-88772 was subsequently included in CISA KEV catalog.
CVE-2026-87902 - Remote File Inclusion vulnerability in WordPress Core
A Remote File Inclusion vulnerability in WordPress Core allowed an unauthenticated attacker to force page-template resolution to include a chosen readable local .php file outside the active theme directories, leading to remote code execution. The flaw resided in the locate_template() function, which resolved caller-supplied template names against theme directories without verifying the result stayed within them, and was reachable through the get_page_template() function via the URL-derived pagename query variable. Exploitation required the active theme to contain a top-level directory beginning with page- and a readable .php target accessible to the web-server account. A public proof-of-concept triggered active exploitation within hours of disclosure, with Wordfence blocking over 548,000 attacks within 24 hours. WordPress addressed the vulnerability in version 7.1.2 with backported fixes across all supported branches, and CISA subsequently added CVE-2026-87902 to the KEV catalog.
What did Cytellite sensors detect this week?
Cytellite telemetry captured active exploit attempts and mass scanning campaigns against exposed services globally. The data highlights which vulnerabilities are under attack and provides source IPs and payloads to authorized teams for detailed threat analysis and validation.
Which vulnerabilities were abused by malware this week?
Active malware campaigns exploited specific vulnerabilities to deliver payloads and carry out post-exploitation actions. Each targeted vulnerability is proactively monitored, manually analysed, and mapped to MITRE ATT&CK tactics and techniques. Insights are derived from the LOVI vulnerability intelligence platform, which aggregates and curates data from multiple sources, OSINT groups, blogs, and data leak sites.
UTA0565's typosquatted websites deploy shared zero-day exploit chain and CLEANGULP backdoor
According to Volexity, in a continuation of its previously published research documenting UTA0560 and JungleBamboo chaining Chrome and Windows zero-day exploits, a third Chinese APT actor tracked as UTA0565 exploited the same chained vulnerabilities (CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880) on September 3-4, 2026, distinguishing its campaigns by using multiple fake websites that typosquatted legitimate media organizations, an NGO, halal restaurant search sites, and corporate training organizations to deceive victims. UTA0565 delivered phishing emails masquerading as entities including the Center for American Progress and content supporting an imprisoned Hong Kong activist, redirecting victims to spoofed domains that loaded a hidden iframe containing the exploit chain, which downloaded chrome_cleanup.exe in-process, removed its Mark of the Web, and launched it via COM. The final payload belonged to a previously undocumented malware family tracked as CLEANGULP, written in C and heavily obfuscated through control flow flattening and indirect calls, which installed itself to %LOCALAPPDATA% as MicrosoftIME.exe, established persistence through a scheduled task, and supported commands including shell execution, process listing, file upload and download, and beacon object file execution while communicating with a typosquatted C2 domain over AES-256-GCM encrypted HTTP traffic. Volexity assessed the widespread adoption of the same exploit kit across multiple Chinese threat actors as indicative of a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by separate groups.
What were the most trending OSS vulnerabilities this week?
Open-Source Software (OSS) vulnerabilities are security weaknesses discovered in publicly available codebases that can be exploited across widely used libraries, frameworks, and tools, often impacting thousands of downstream applications.
Were any PRE-NVD vulnerabilities identified this week?
PRE-NVD vulnerabilities refer to security flaws that are discovered, discussed, or even exploited in the wild before their official inclusion in the National Vulnerability Database (NVD). These early-stage vulnerabilities often emerge through threat actor chatter, exploit proof-of-concepts, and technical disclosures shared across social media platforms and underground forums, signaling potential exploitation risks before public awareness.
Conclusion
Zero-day exploitation that outpaced vendor disclosure timelines, emergency pre-notification warnings from national CERTs, and post-disclosure weaponization measured in hours defined this week's threat landscape. Attackers demonstrated that patching alone remained insufficient, as persistent backdoor accounts, in-memory webshells, and scheduled re-creation scripts survived remediation across multiple products. The coordinated sharing of exploit chains across three independent Chinese APT groups underscored the industrialization of zero-day development and distribution. Loginsoft Vulnerability Intelligence (LOVI) continued to deliver timely exploitation timelines, threat actor attribution, and actionable intelligence to support proactive defense across these evolving threats.
FAQs
1) Why do exploitation attempts spike within hours of a vulnerability being publicly disclosed?
Attackers actively monitor vendor advisories, patch diffs, and security research publications to reverse-engineer vulnerabilities and build working exploits. Once technical details or proof-of-concept code become available, automated scanning and exploitation at scale follow almost immediately, leaving organizations that have not yet patched with a rapidly shrinking window of safety.
2) Is patching sufficient to fully remediate actively exploited vulnerabilities?
Patching prevents new exploitation but does not remove access already established by attackers. Threat actors routinely plant persistent backdoor accounts, scheduled re-creation scripts, and in-memory webshells that survive updates. Organizations should treat any system that had a window of exposure as potentially compromised and investigate for indicators of persistence before considering remediation complete.
3) Does inclusion in the CISA KEV catalog mean exploitation is widespread?
Not necessarily widespread - but confirmed. KEV inclusion indicates verified in-the-wild exploitation. While the scale may vary, the operational reality is that threat actors possess working exploits, making patch prioritization urgent regardless of observed targeting volume.
4) How does LOVI help organizations manage vulnerabilities effectively?
Loginsoft Vulnerability Intelligence empowers you to efficiently prioritize and respond to potential vulnerabilities by focusing on those actively exploited in the wild. LOVI correlates vulnerability data with real-world threat activity to reduce noise and improve decision-making. This approach enables faster remediation and stronger security posture.
5) What is Cytellite?
Cytellite is a Loginsoft security intelligence platform that provides real-time visibility into emerging threats through a global sensor network. It delivers actionable IP intelligence to help organizations detect, analyze, and respond to attacks quickly. By correlating threat data with live activity, Cytellite strengthens resilience across dynamic threat landscapes.

