Security Roundup: Netlogon 0-Click RCE, Citrix NetScaler SAML Exploit, TeamPCP Supply Chain, Android Zero-Day — Week of June 4, 2026

Weekly briefing: Windows Netlogon 0-click DC takeover, Citrix NetScaler SAML memory overread, and TeamPCP supply chain backdoor.

Security Roundup: Netlogon 0-Click RCE, Citrix NetScaler SAML Exploit, TeamPCP Supply Chain, Android Zero-Day — Week of June 4, 2026

A week defined by unauthenticated remote code execution at the Windows domain controller layer, large-scale exploitation of Citrix's SAML identity stack, a two-month supply chain campaign that backdoored developer tools trusted by millions, and an actively exploited Android Framework zero-day. Here is what you need to know and act on.


1. CVE-2026-41089 — Windows Netlogon 0-Click RCE Under Active Exploitation (CVSS 9.8)

A stack-based buffer overflow in Windows Netlogon (netlogon.dll) allows an unauthenticated attacker with network access to a domain controller to achieve remote code execution as SYSTEM. No authentication, user interaction, or prior access is required — a single crafted NetrServerAuthenticate3 request is sufficient to trigger the overflow. Active exploitation was confirmed May 29, 2026, with Belgium's Centre for Cybersecurity issuing a public warning. A public proof-of-concept is available.

CVSS: 9.8 Critical | CVE: CVE-2026-41089 | Affected: Windows Server 2016/2019/2022/2025 (all pre-June 2026 Patch Tuesday builds)

Attack chain: Attacker enumerates DCs via DNS SRV records → sends oversized credential blob via unauthenticated DCE/RPC → overflows Netlogon stack buffer → executes ROP chain → SYSTEM shell → DCSync / krbtgt extraction → Golden Ticket persistence.

Remediation: Apply June 2026 Patch Tuesday updates to all domain controllers in a single maintenance window (partial patching creates an exploitable gap). Verify KB5060842 (Server 2022), KB5060840 (Server 2019), or KB5060836 (Server 2025) is installed. Block unauthenticated RPC to DCs at the network boundary as a short-term control.


2. CVE-2026-3055 — Citrix NetScaler SAML IDP Memory Overread: Large-Scale Exploitation Confirmed (CVSS 9.3)

Fortinet confirmed large-scale active exploitation of CVE-2026-3055, an out-of-bounds memory read in Citrix NetScaler ADC/Gateway when configured as a SAML IDP. Attackers send a bare wctx query parameter (without an = value) to /saml/login, causing the NSC_TASS handler to read and return stale memory from prior requests. Leaked data has included session cookies, HTTP Authorization headers, and partial SAML assertions.

CVSS: 9.3 Critical | CVE: CVE-2026-3055 | CISA KEV: March 30, 2026 | Affected: NetScaler ADC/Gateway < 14.1-43.12, 13.1 < 13.1-57.10, 13.0 (EOL)

Attack chain: Probe /cgi/GetAuthMethods for SAML IDP → send GET /saml/login?wctx → harvest leaked memory for session tokens → replay tokens against downstream SAML service providers.

Remediation: Upgrade to NetScaler 14.1-43.12+ or 13.1-57.10+. If upgrade is not immediately possible, disable SAML IDP (set authentication samlIdPProfile -DISABLED) or deploy WAF rules to block requests matching /saml/login with a bare wctx parameter.


3. TeamPCP Supply Chain Campaign — Trivy, KICS, and Bitwarden CLI Backdoored

A threat actor tracked as TeamPCP ran a two-month coordinated supply chain campaign (February–April 2026) that compromised three widely-used open-source developer and security tools. The campaign began with incomplete credential rotation in Aqua Security's Trivy repository, allowing the attacker to inject credential-stealing malware on March 16. Stolen credentials then facilitated backdooring of Checkmarx KICS (April 22) and the Bitwarden CLI npm package (@bitwarden/[email protected]) on the same day. The Bitwarden package was live for ~90 minutes and received 334 downloads before removal. All three implants share a C2 domain (telemetry-cdn[.]dev) and exfiltrated cloud credentials, SSH keys, Kubernetes configs, and password vault contents. Downstream impact confirmed at OpenAI and Vercel developer environments.

Affected versions: Trivy (Mar 16–22 builds), checkmarx/kics:v2.1.4, @bitwarden/[email protected]

IOC: C2 domain telemetry-cdn[.]dev (185.220.101[.]47), X-Client-ID HTTPS POST header to this IP.

Remediation: If any of these package versions ran in your environment, immediately rotate all secrets (AWS keys, GCP SAs, GitHub tokens, SSH keys, Docker registry tokens). Block the C2 domain/IP at DNS and firewall. Upgrade to Trivy ≥0.62.0, KICS latest (post–Apr 25), Bitwarden CLI ≥2026.5.0.


4. CVE-2025-48595 — Android Framework Zero-Day Patched, CISA KEV (CVSS 7.8)

Google's June 2026 Android Security Bulletin patches CVE-2025-48595, an integer overflow in the Android Framework's Binder IPC handler that allows a local attacker to escalate privileges to the system uid. The vulnerability has been exploited in the wild as Stage 2 of multi-stage attack chains — following initial code execution via sideloaded malicious apps or WebView exploits — to install persistent stalkerware with access to SMS, call logs, location, and app data. CISA added it to the KEV catalog June 2, 2026, with a June 23 remediation deadline for FCEB agencies.

CVSS: 7.8 High | CVE: CVE-2025-48595 | CISA KEV: June 2, 2026 | Affected: Android 14 and 15 prior to 2026-06-01 patch level

Remediation: Apply the June 2026 Android Security Bulletin (patch level 2026-06-01 or 2026-06-05). For enterprise environments, push the update via MDM within 72 hours. Verify patch level via Settings → About Phone → Android Security Patch Level.


5. CISA Adds CVE-2022-0492 — Linux Kernel Container Escape Returns to KEV

CISA added CVE-2022-0492, a Linux kernel privilege escalation and container escape vulnerability in the cgroups subsystem, to the KEV catalog on June 2, 2026. The flaw — a missing capabilities check in the release_agent mechanism — was originally patched in 2022, but evidence of renewed active exploitation in containerized cloud environments has prompted CISA to re-flag it. Attackers with access to a container running on an unpatched kernel can escape to the host via writing a malicious release_agent if the container has CAP_DAC_OVERRIDE or root inside the container.

CVE: CVE-2022-0492 | CISA KEV: June 2, 2026 | Affected: Linux kernels prior to 5.17.2, or distributions that have not backported the fix

Remediation: Ensure kernel is patched (Linux ≥5.17.2 or distro-patched equivalent). For container environments, enable seccomp profiles, AppArmor/SELinux policies, and ensure containers do not run with --privileged or excess Linux capabilities. Verify with:

uname -r   # Confirm kernel version
# For Kubernetes clusters, scan nodes with trivy (clean version):
trivy node --scanners vuln 2026-06-04-kernel-check

Deep Dives

For full technical analysis, attack chain breakdowns, IOCs, and remediation commands, see the individual deep-dive posts:

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther