A September 30, 2026 threat forecast warns of a convergence of critical remote code execution (RCE) vulnerabilities being actively exploited against internet-facing enterprise systems. The most immediate threats are two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772. Both flaws were exploited before patches were available and have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Simultaneously, the threat group ShinyHunters (UNC6240) has re-weaponized a critical vulnerability in Oracle PeopleSoft, CVE-2026-35273, using new techniques to bypass Web Application Firewalls (WAFs). Organizations are urged to treat any unpatched, internet-facing NetScaler and PeopleSoft instances as compromised and prioritize immediate patching and investigation.
All three vulnerabilities are under active and widespread exploitation. The Citrix flaws are being used as zero-days, indicating sophisticated threat actors. The re-weaponization of the PeopleSoft flaw by a known group like ShinyHunters suggests a focused campaign to steal data from high-value ERP systems. The combination of these perimeter and application-level RCEs creates a highly dangerous environment for defenders.
The compromise of these systems can lead to severe consequences:
The following patterns may help identify vulnerable or compromised systems:
httpaccess.log / httpsaccess.lognsppe processD3-NTA: Network Traffic Analysis.The primary and most effective mitigation is to apply the security patches provided by Citrix and Oracle immediately.
Mapped D3FEND Techniques:
Restrict network access to the management interfaces of Citrix NetScaler and PeopleSoft systems to only authorized personnel and trusted IP ranges.
Mapped D3FEND Techniques:
Use a Web Application Firewall (WAF) with up-to-date rules to block known exploit patterns, though be aware that attackers are actively developing bypasses.
Mapped D3FEND Techniques:
The most critical and immediate action for organizations is to apply the security patches released by Citrix and Oracle. For CVE-2026-88771, CVE-2026-88772, and CVE-2026-35273, these are not routine updates; they are emergency changes that must be deployed immediately due to active, widespread exploitation. Prioritize all internet-facing Citrix NetScaler ADC/Gateway and Oracle PeopleSoft instances. Because these are zero-day or near-zero-day exploits, waiting for a standard patch cycle is not an option. The 'assume compromise' principle should be applied: any unpatched, internet-facing device should be considered compromised. Patching not only fixes the vulnerability but is also a critical step in evicting an attacker who may have already gained access. After patching, it is essential to proceed with threat hunting to look for signs of post-exploitation activity.
As a compensating control and defense-in-depth measure, organizations must implement strict inbound traffic filtering for their critical appliances. Access to the management interfaces of Citrix NetScaler and Oracle PeopleSoft systems should never be exposed to the public internet. Create explicit firewall rules that only allow access from a limited set of internal, trusted IP addresses (e.g., a dedicated management bastion host or SOC network). For the application interfaces themselves, deploy a Web Application Firewall (WAF) with rules specifically designed to detect and block the exploit patterns for these CVEs. While the report notes that ShinyHunters has developed a WAF bypass for the PeopleSoft flaw, a well-configured WAF can still defeat less sophisticated attempts and provide valuable logging for threat hunting.
CISA adds CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog.
A threat forecast is issued highlighting the convergence of Citrix and Oracle exploits.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.