ThreatPaper

#edge-device

2 cases

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 were exploited from at least September 3, 2026, three weeks before the September 27 patch. Web shells survive the update; attribution is still only suspected.

Malware

A maximum-severity SonicWall SMA1000 SSRF was exploited as a zero-day three weeks before its July patch. Volexity's UTA0533, a separate credential-harvesting operator, and an INC Ransomware affiliate all piled on — one ran Impacket secretsdump from the appliance to DCSync seven domain controllers.

MalwareState-SponsoredRansomware