Security Roundup: Citrix NetScaler Active Zero-Days, Microsoft SharePoint KEV, Kiteworks Precautionary Shutdown (Weekend Edition - September 28, 2026)

ColibriSec Weekend Security Roundup September 28 2026

Executive Summary: The weekend of September 26–28, 2026, unleashed one of the most critical sequences of edge appliance emergencies and AI-augmented cyber offensives of the year. Citrix released urgent out-of-band updates and CTX697096 advisories for two actively exploited zero-day Remote Code Execution (RCE) flaws in NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772), prompting immediate CISA KEV additions. Simultaneously, CISA set an emergency September 28 patching deadline for Microsoft SharePoint code injection RCE (CVE-2026-65660), Kiteworks orchestrated an unprecedented global defensive shutdown, and Spanish railway operators Adif and Renfe disclosed an AI-augmented infrastructure intrusion. Here is the full strategic briefing and technical breakdown.

🏛️
HIGH-SEVERITY PERIMETER & CRITICAL INFRASTRUCTURE ALERT Advanced persistent threat groups and ransomware syndicates are actively weaponizing appliance zero-days, unsafe enterprise deserialization, and AI-accelerated automated reconnaissance. Citrix NetScaler ADC & Gateway dual zero-days (CVE-2026-88771 & CVE-2026-88772) under active global exploitation CISA emergency KEV mandate for Microsoft SharePoint Server Code Injection RCE (CVE-2026-65660) Kiteworks executes unprecedented precautionary 9-hour global customer shutdown following credible zero-day intelligence Spanish rail operators Adif and Renfe suffer 500GB breach in landmark AI-assisted cyberattack ShinyHunters hacker syndicate launches retaliatory leak wave following Amsterdam arrest of key figure Qilin ransomware claims 15% of all global attacks, deploying LLM-generated Active Directory kill-scripts

Key Threat Disclosures at a Glance

1. Citrix NetScaler Dual Zero-Day RCE (CVE-2026-88771 & CVE-2026-88772)

On Sunday, September 27, Citrix disclosed eight vulnerabilities across NetScaler ADC and Gateway, led by two CVSS 9.5 zero-day flaws exploited in the wild prior to disclosure. CVE-2026-88771 is an unauthenticated input validation vulnerability in default configurations allowing direct remote command injection. CVE-2026-88772 is a critical memory overflow in the Datagram Transport Layer Security (DTLS) subsystem of VPN virtual servers, crashing packet engine processes (nsppe) and enabling arbitrary shellcode execution. CISA immediately added both to the KEV catalog, mandating remediation by September 30 while warning organizations to preserve memory dumps before updating.

2. Microsoft SharePoint Server Code Injection in CISA KEV (CVE-2026-65660)

Initially downplayed as a spoofing issue, CVE-2026-65660 has been reclassified as a critical CVSS 8.8 Remote Code Execution vulnerability in on-premises Microsoft SharePoint Server. Attackers exploit unsafe deserialization during workflow engine state transitions to execute arbitrary code within the context of the SharePoint application pool identity (w3wp.exe). CISA added the flaw to the KEV catalog with a mandatory deadline of September 28, 2026.

3. Kiteworks Emergency Precautionary Global Shutdown

In a dramatic defensive maneuver on September 25–27, enterprise secure content platform Kiteworks urged all self-managed customers to initiate a synchronized nine-hour shutdown of their "Advanced Forms" appliances. Federal authorities shared credible threat intelligence indicating an imminent zero-day exploit chain being prepared by an APT syndicate. Following rapid hotfix deployments and log analysis, the shutdown was safely lifted on September 27 with zero confirmed customer breaches—a textbook case of proactive defense.

4. Adif & Renfe Spanish Railway AI-Augmented Intrusion

Spanish national rail infrastructure manager Adif and rail carrier Renfe disclosed an interconnected cyber incident resulting in the unauthorized access of approximately 500GB of passenger telemetry, routing data, and system logs. Notably, investigators confirmed this was the first public sector infrastructure attack in Spain utilizing automated AI agents to discover perimeter API flaws and orchestrate credential stuffing without human latency.

5. ShinyHunters Syndicate Retaliation Post-Amsterdam Arrest

Dutch law enforcement in Amsterdam confirmed the arrest of 24-year-old security professional Pepijn van der Stap, identified as an alleged key broker and operator for the ShinyHunters cybercrime syndicate. Within 48 hours, remaining syndicate members retaliated by dumping compromised databases, including data from previous intrusions at telecom provider Odido and an FBI job applicant portal.

6. Qilin Ransomware Reaches 2026 Record High

Threat telemetry published over the weekend shows August and September 2026 ransomware activity reaching unprecedented heights (>1,070 monthly incidents), with the Qilin syndicate capturing 15% of the total volume. Qilin affiliates are now deploying sophisticated Python and PowerShell wiper scripts generated using large language models (LLMs) to systematically demolish Active Directory trusts, volume shadow copies, and immutability flags.

Technical Deep Dives in This Series

Weekend Action Checklist for Security Operations

  1. Capture NetScaler Forensics Then Patch: Before applying Citrix CTX697096 security updates, archive /var/crash and /var/core to preserve volatile packet engine evidence. Upgrade to 14.1-38.48+, 13.1-58.32+, or 13.0-92.42+ immediately.
  2. Remediate SharePoint Server Immediately: Ensure all on-premises SharePoint 2016, 2019, and Subscription Edition servers have applied Microsoft's September cumulative updates before the September 28 CISA deadline.
  3. Audit DTLS Listeners: Temporarily disable DTLS on public NetScaler Gateway vServers (set vpn vserver <name> -dtls OFF) if patching cannot be completed immediately.
  4. Harden Active Directory Against AI Kill-Scripts: Implement Tier 0 administrative isolation, restrict PowerShell script block execution, and enforce immutable, air-gapped backup retention.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther