Follow the latest coverage, related explainers and connected technology stories.
CISA added the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 to its catalog of exploited vulnerabilities and gave U.S. civilian federal government agencies until September 30 to secure the affected devices. The two vulnerabilities enable unauthenticated remote command execution, while Citrix warned that indicators of compromise may not reveal all cases of compromise.
Check Point confirmed that two vulnerabilities in Security Gateway are being actively exploited, one enabling remote command execution before authentication, while the other has been exploited as a zero-day since July 23, 2026. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving U.S. federal agencies until September 25 to apply fixes or mitigation measures.
CISA added CVE-2026-7273 in Zyxel GS1900 switches to its catalog of exploited vulnerabilities and ordered U.S. federal civilian agencies to address it by Thursday. GreyNoise says attackers exploited the vulnerability to compromise 996 switches in 48 countries.