Observed Signal · Sep 28, 2026 · Market Signal · Source: Sophos · Impact: 2/5

Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

Executive Signal Summary

New blog post published September 28, 2026: Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation.

SIGNAL RADAR

Track Sophos Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: Sophos•Published: Sep 28, 2026

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Layer 1: Core IT, Operations & FoundationFeb 26, 2026

Critical Cisco Bug Exploited Since 2023, Global Alert Issued

Cisco disclosed a critical vulnerability (CVSS 10.0) in its Catalyst SD‑WAN product family that allows remote attackers to gain full, persistent privileged access to affected devices. Cisco’s researchers found evidence of exploitation dating back to 2023, and some impacted organizations are described as critical infrastructure. Governments including Australia, Canada, New Zealand, the United Kingdom and the United States issued warnings; U.S. agency CISA ordered civilian federal agencies to patch by the end of the specified Friday citing imminent threat. Cisco and governments did not publicly attribute the attacks to a named threat actor, though Cisco tracked a cluster of activity as UAT‑8616. The disclosure follows a December advisory for another actively exploited Cisco vulnerability in Async software.

Read assessment
SecurityJul 28, 2026

FortiOS CVE-2025-68686 Symlink Mitigation Bypass

CVE-2025-68686 is an actively exploited FortiOS vulnerability that allows attackers who already have file-system access to bypass symlink persistence mitigations via crafted HTTP requests to the SSL‑VPN web interface. The flaw can expose sensitive files (configurations, credentials, keys) even after firmware upgrades. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 27, 2026. Affected FortiOS versions include 6.4, 7.0, 7.2, 7.4.0–7.4.6 and 7.6.0–7.6.1; vendor fixes are available in 7.4.7, 7.6.2 or later. Successful exploitation requires a prior file‑system compromise; remediation guidance includes rebuilding devices, removing artifacts, rotating secrets, and restricting SSL‑VPN exposure.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.