#edge-device
2 cases
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 were exploited from at least September 3, 2026, three weeks before the September 27 patch. Web shells survive the update; attribution is still only suspected.
Malware
SonicWall SMA1000 (CVE-2026-15409): one CVSS-10 SSRF, three threat clusters, Active Directory theft from the applianceMalwareState-SponsoredRansomware
A maximum-severity SonicWall SMA1000 SSRF was exploited as a zero-day three weeks before its July patch. Volexity's UTA0533, a separate credential-harvesting operator, and an INC Ransomware affiliate all piled on — one ran Impacket secretsdump from the appliance to DCSync seven domain controllers.
MalwareState-SponsoredRansomware