Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
Weekly roundup: NetScaler, Apple, Cisco SD-WAN, and FortiMail zero-days exploited; Microsoft analytics flaw disclosed.
Help Net Security's weekly roundup centers on several actively exploited zero-days. Citrix patched NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772 after weeks of global exploitation that planted webshells, and Mandiant linked early CVE-2026-88772 intrusions to suspected state-sponsored actors. Apple fixed exploited Core Graphics bug CVE-2026-86950, Cisco reported in-the-wild SD-WAN flaw CVE-2026-76504, and Fortinet warned of FortiMail zero-day CVE-2026-104286. The digest also notes a Microsoft Titan analytics flaw affecting up to 17 trillion rows, an OpenInfra JFrog Artifactory compromise, ShinyHunters claims against FBI job portals, a suspected KillSec arrest, and Google's Gemini 4 Argon.