Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack
CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.
CISA KEV adds Cisco ISE and Acronis Backup flaws: what defenders should patch first
CISA has added CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog. Both sit in infrastructure that attackers value: network access control and backup.
CISA Adds Seven Actively Exploited Flaws to KEV — Shells and Miners Follow
A fresh CISA KEV batch spans SonicWall, Sangoma, JFrog, Kestra and LiteLLM — and in several cases the exploitation has already moved past initial access to reverse shells and cryptomining.
CISA KEV Alert: Ray's Browser-Triggered RCE Flaw Is Now Actively Exploited
A critical Ray vulnerability lets a malicious webpage hijack a developer's local AI cluster through DNS rebinding — CISA's KEV listing confirms it's no longer theoretical.