View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Citrix NetScaler CVE-2026-8452 exploited in the wild

🚨 ACTIVE EXPLOITATION

  • CISA lists Red Hat Libuser race condition CVE-2015-3246 as exploited CVE-2015-3246
    CISA has added a Red Hat Libuser race condition to its Known Exploited Vulnerabilities catalog.

    • Red Hat Libuser installations are affected.
    • Authenticated local users can exploit the race condition to corrupt /etc/passwd.
    • The flaw can cause denial of service or privilege escalation.
    • CISA lists CVE-2015-3246 in its Known Exploited Vulnerabilities catalog.
      πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV
  • CVE-2015-5287: Red Hat ABRT privilege-escalation flaw exploited CVE-2015-5287
    CISA lists a Red Hat ABRT privilege-escalation flaw as actively exploited.

    • Red Hat Automatic Bug Reporting Tool (ABRT) users are affected.
    • The sosreport functionality mishandles symbolic links and uses predictable filenames.
    • A local attacker with certain permissions can exploit a symlink attack to gain privileges.
      πŸ“„ Source: nvd.nist.gov Β· πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV
  • CISA KEV lists CVE-2019-1068 SQL Server remote-code flaw CVE-2019-1068
    CVE-2019-1068 is an exploited remote-code-execution flaw in Microsoft SQL Server.

    • Microsoft SQL Server customers are affected.
    • The vulnerability enables remote code execution in the SQL Server Database Engine service account context.
    • CISA lists CVE-2019-1068 in its Known Exploited Vulnerabilities catalog.
      πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV
  • UAT-10147 Exploited AjaxPro CVE-2021-23758 Against Web Servers CVE-2021-23758
    UAT-10147 exploited AjaxPro CVE-2021-23758 for remote code execution on web servers.

    • Government, education, media, technology, and gaming organizations using Windows or Linux web servers were targeted.
    • Ajax.NET Professional (AjaxPro) was vulnerable to unsafe deserialization of untrusted data, enabling arbitrary .NET class execution.
    • UAT-10147 used the publicly disclosed CVE-2021-23758 in automated, AI-assisted intrusion campaigns alongside Metasploit and ysoserial.
    • Compromised servers were used to deploy web shells, BadIIS, Noodle RAT, SPECTRE, or Meterpreter for SEO fraud, data theft, and persistence.
    • The campaign's exposed infrastructure included 139.180.197[.]150 and a target list of roughly 170,000 URLs.
      πŸ“„ Source: nvd.nist.gov Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via CISA KEV
  • UAT-10147 exploits Linux kernel CVE-2022-0995 for privilege escalation CVE-2022-0995
    UAT-10147 exploits CVE-2022-0995 to escalate privileges on Linux web servers.

    • The flaw affects Linux kernel systems, including web servers in government, education, media, technology and gaming sectors.
    • CVE-2022-0995 is an out-of-bounds write in the kernel’s watch_queue event notification mechanism.
    • An unprivileged local user can write arbitrary data out of bounds to gain elevated privileges or cause denial of service.
    • UAT-10147 uses the flaw after web-server compromise alongside other privilege-escalation exploits and deploys web shells, NoodleRAT, SPECTRE or Meterpreter.
    • Talos linked the campaign to command-and-control infrastructure at 139.180.197[.]150.
      πŸ“„ Source: nvd.nist.gov Β· πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV
  • UPDATE: Citrix NetScaler CVE-2026-8452 exploited in the wild CVE-2026-8452
    Attackers are exploiting a pre-authentication memory overflow in Citrix NetScaler.

    • Citrix NetScaler ADC and NetScaler Gateway deployments configured as Gateway or AAA virtual servers are affected.
    • Versions before ADC/Gateway 14.1-72.61, 13.1-63.18, FIPS 14.1-72.61, and FIPS/NDcPP 13.1-37.272 are vulnerable.
    • A specially crafted SAML message triggers a heap overflow during signature validation without authentication.
    • Public proof-of-concept code demonstrates denial of service and potential pre-authentication remote code execution; exploitation has been reported in the wild.
      πŸ“„ Source: support.citrix.com Β· πŸ“Ž Coverage: bishopfox.com Β· πŸ‘ via CISA KEV

πŸ’₯ BREACHES & INCIDENTS

  • (no items)

πŸ”“ CVEs & KEV

  • CVE-2026-54523 β€” CVSS 9.6 β€” Kyverno Critical Cross-Namespace Resource Creation (CVE-2026-54523)

  • CVE-2026-76784 β€” CVSS 8.7 β€” Insufficient Cryptographic Protections in Local Device Communication Protocol...

  • CVE-2026-58474 β€” CVSS 8.6 β€” whichllm before 0.5.16 Code Injection via run and snippet commandswhichllm before ...

  • CVE-2026-32258 β€” CVSS 8.1 β€” Winter: Stored XSS through Editor Settings custom stylesWinter is a free, ope...

  • CVE-2026-32257 β€” CVSS 8.1 β€” Winter: Stored XSS through Brand Settings custom stylesWinter is a free, open...

  • CVE-2026-47841 β€” CVSS 7.4 β€” WebAuthn User Verification Bypass via Session SerializationAn application usi...

  • CVE-2026-47836 β€” CVSS 7.2 β€” Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVNThe bas...

  • CVE-2026-35445 β€” CVSS 7.1 β€” Winter: Authenticated backend users can bypass Users controller permission ch...

  • CVE-2026-32639 β€” CVSS 6.8 β€” Winter: Broken access control in Cms\Controllers\Index allows cross-templat...

  • CVE-2026-47837 β€” CVSS 6.8 β€” Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Request...

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • GPUThor Rowhammer Attack Bypasses NVIDIA GPU ECC for Root Access
    GPUThor bypasses ECC protections on NVIDIA GPUs.

    • NVIDIA GPU users relying on ECC memory are affected.
    • The attack can cause denial of service and root-level privilege escalation.
    • GPUThor uses Rowhammer to bypass GPU error-correcting code protections.
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer
  • Nimbus Manticore Adds TWOSTROKE-Like Backdoor and Reverse SSH Tool
    Group-IB has identified new Nimbus Manticore malware and infrastructure.

    • The activity targets defense, aerospace, IT service providers, and military organizations in the Middle East, Europe, and the United States.
    • A Windows C++ backdoor collects system information, executes commands, manages files, and supports persistence.
    • The backdoor masquerades as wtsapi32.dll and uses HTTPS to connect to hard-coded C2 servers.
    • A reverse SSH tool disguises itself as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 over port 443.
      πŸ“„ Source: group-ib.com Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Microsoft details attacks targeting LiteLLM, RAGFlow and Kestra AI workloads
    Microsoft observed attackers compromising exposed AI infrastructure to steal credentials and monetize compute.

    • Organizations deploying LiteLLM gateways, RAGFlow retrieval platforms, and Kestra workflow environments are affected.
    • Attackers targeted model-provider keys, database connection strings, tenant credentials, workflow access, and host compute.
    • LiteLLM intrusions likely exploited CVE-2026-42271 and CVE-2026-48710 for remote code execution.
    • RAGFlow activity involved possible SSRF reconnaissance, code execution, and a Python hook that intercepted LLM credentials.
    • Kestra attacks used workflow-originated shell execution, container discovery, XMRig cryptomining, and data collection.
      πŸ“Ž Coverage: microsoft.com Β· πŸ‘ via Microsoft Security Blog
  • PATCHCORD malware targets Afghan telecoms and South Asian infrastructure
    Transparent Tribe is targeting Afghan telecoms and South Asian infrastructure with PATCHCORD malware.

    • Afghan telecom providers and South Asian critical infrastructure organizations are targeted.
    • Transparent Tribe, also known as APT36, uses the custom C/C++ PATCHCORD backdoor.
    • Phishing lures impersonate AFTEL VPN installers and telecom or network-management tools.
    • PATCHCORD executes code in memory, fingerprints hosts, enumerates processes, and checks for sandboxes.
    • The malware persists by hijacking browser shortcuts; related Sheetcord uses Windows startup and Google Sheets for C2.
      πŸ“Ž <https://www.reddit.com/r/netsec/comments/1vz6179/patchcord

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check