Sep 29: Citrix KEV Deadline, PeopleSoft Live Campaign
CISA's Citrix patch deadline is September 30. ShinyHunters is running a live Oracle PeopleSoft exploit campaign. Plus: JADEPUFFER on Azure, and a $387M crypto heist closed out.
- CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV catalog with a federal patch deadline of September 30. Both allow unauthenticated RCE against NetScaler ADC and Gateway.
- ShinyHunters retooled its CVE-2026-35273 exploit and launched a broader campaign against Oracle PeopleSoft, per a Google Threat Intelligence advisory published September 28.
- JADEPUFFER-linked operators are using compromised Azure service principals with excessive permissions to delete cloud resources across targeted tenants.
- Obot AI platform patched three CVEs including an unauthenticated Docker socket exposure. Bitget resumed withdrawals after a $387.5M DPRK-linked theft.
Two critical Citrix NetScaler CVEs that CISA added to its Known Exploited Vulnerabilities catalog last weekend carry a federal patch deadline of September 30. That is tomorrow. Full coverage.
CVE-2026-88771 and CVE-2026-88772 both allow unauthenticated remote code execution against NetScaler ADC and Gateway. Exploitation was confirmed before Citrix released patches. If you run NetScaler ADC or Gateway: check Citrix’s advisory, apply the update, and verify no unauthorized appliance modifications before patching.
Oracle PeopleSoft: ShinyHunters running a live campaign
Google Threat Intelligence published a warning September 28 that ShinyHunters has retooled its CVE-2026-35273 exploit and started a broader campaign against Oracle PeopleSoft. The previous iteration burned that access path against specific, known targets. This run is wider. Coverage.
If any PeopleSoft instance in your environment is externally reachable and has not been patched for CVE-2026-35273: take it offline or block external access until it is. Google’s advisory does not indicate the campaign is finished.
JADEPUFFER: Azure service principals as the entry point
Microsoft Threat Intelligence documented how JADEPUFFER-linked operators are using compromised Azure service principals to delete resources across targeted tenants. The attack does not rely on a new Azure platform vulnerability. It relies on service principals that have accumulated excessive permissions with no monitoring on their activity. Coverage.
Review what service principals exist in your tenant, what roles they hold, and whether any have changed recently.
Also since September 22
-
Obot AI platform patched three CVEs in GitHub Security Advisories released September 28, including an unauthenticated Docker socket exposure and two MCP endpoint access control failures. If you run Obot, update and restrict Docker socket access. Coverage.
-
Bitget resumed Bitcoin withdrawals September 28, days after a suspected North Korean group stole $387.5 million in a backend credential compromise. No public attribution from Bitget to date; DPRK attribution is from external analysts. Coverage.
The September 30 Citrix deadline is a Binding Operational Directive for FCEB agencies. Non-government operators are not bound by it. Both CVEs are confirmed exploited in the wild and equally exposed.
- 0dayNews — Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
- 0dayNews — ShinyHunters Retooled PeopleSoft Exploit, Google Warns
- 0dayNews — JADEPUFFER Uses Stolen Service Principals to Destroy Azure
- 0dayNews — Obot AI Platform Patches Three CVEs, Two Critical
- 0dayNews — Bitget Resumes Withdrawals After $387.5M DPRK Heist