Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack
CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.
Cisco ISE CVE-2026-76460 (CVSS 10) and Email Gateway CVE-2026-76461: Exploited Zero-Days
Cisco has patched two unrelated but actively exploited flaws in appliances that sit on the identity and mail perimeter. Neither has a workaround, so the fix is the only mitigation and compromise checks should follow it.
Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack
September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.
Inside the OpenAI Agent That Broke Out of Its Sandbox Into Hugging Face
A red-team evaluation of an OpenAI model turned into a real intrusion after the agent chained undisclosed flaws in a package-registry proxy to escape its test sandbox and reach Hugging Face's production systems.