Cyber Threat Brief — September 27 2026

⚠️ This report is AI-generated. Always validate findings.

1. Citrix NetScaler Dual Unpatched RCE Zero-Days (ITW; CVE pending)

TL;DR: watchTowr (2026-09-26): two separate, unpatched remote code execution flaws in NetScaler ADC / NetScaler Gateway were exploited before any fix existed, discovered during forensic investigations. Distinct from KEV auth-bypass CVE-2026-19490 (patched 2026-08-19). Citrix has not published CVE IDs, affected builds, CVSS, workaround, or IoCs as of 2026-09-27; communications and patches expected early week of 2026-09-28. Field reports: private firmware via Sev1 support case; informal NCSC-NL / MSP shutdown advice (no new public NCSC advisory beyond NCSC-2026-0318 for 19489/19490). Treat internet-facing appliances as high risk — isolate or power off where ops allow; assume compromise if exposed during the ITW window.

What’s New:

  • watchTowr confirmed two RCE 0-days + forensic ITW (not rumor-only); explicitly not CVE-2026-19490
  • Admins taking appliances offline; private Sev1 build reported ahead of public bulletin
  • No public IoCs — detection is inventory + compromise assessment, not signature matching

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Unpatched dual RCE on NetScaler ADC / NetScaler Gateway (CVE IDs pending; not CVE-2026-19490 / CVE-2026-19489 / CVE-2026-8452). Builds on Aug fixed train (14.1-73.32, 13.1-63.21) not confirmed safe by Citrix for the new flaws. 13.1 End of Maintenance 2026-09-15 — patch eligibility unclearVulnerable edge VPN/ADC / 0-dayT1190NetScaler inventory / Citrix supportOpen Sev1 for private firmware; watch Citrix Security Bulletins; prefer isolate/power-off internet-facing VIP until public advisory
Management plane internet exposure; crash dumps under /var/core (nsppe); remote syslog / NetScaler Console logs; VPX snapshot + tech support bundleForensic / exposureT1190 / T1082NetScaler FS / syslogPer Citrix suspected-compromise guidance: preserve evidence first, then isolate; keep Management Services off public internet; rotate service-account secrets, user passwords that authenticated through the appliance, and revoke certs/keys
NCSC-NL citrix-2025 compromise-check scripts (live host / core dump / disk image) — written for 2025 NetScaler ITW (e.g. CVE-2025-6543 class); not specific to these unpublished flawsHunt toolingT1082Offline image / live applianceRun as best-effort post-incident check (github.com/NCSC-NL/citrix-2025); negative result ≠ clean for the new 0-days

Detection

SourceRuleGap
Splunk ESCUNone — verified search for these unpublished 0-days. Prior Citrix analytics target different CVEs (CitrixBleed2 CVE-2025-5777 /p/u/doAuthentication.do; CitrixBleed CVE-2023-4966 OpenID config; CVE-2023-3519 VPN paths) — rejected as wrong vuln classNo HTTP/IoC signature exists publicly for the new pair
ElasticNone — verified search for NetScaler 2026 dual-RCE 0-dayNo emerging-threat rule without CVE/IoC
SigmaNone — verified search (existing ET rules are CVE-2019-19781 / CVE-2020-8193 / CVE-2023-4966)No rule for unpublished 2026 dual RCE

Hunt hint: (1) Inventory all ADC/Gateway; note internet-facing AAA/Gateway VIPs. (2) Sev1 + isolate if exposed. (3) Preserve /var/core, remote syslog, Console logs before wipe/rebuild. (4) After private/public patch: still run compromise assessment — patch does not undo pre-patch foothold.

Sources: The Hacker News 2026-09-27, watchTowr Infosec.exchange, Cyber Kendra, THN X, NCSC-NL citrix-2025, Threadlinqs TL-2026-2682


2. Addify Request a Quote for WooCommerce Unauth PHP Upload — CVE-2026-18143

TL;DR: Wordfence-assigned CVE-2026-18143 (CVSS 9.8, CWE-434): unauthenticated arbitrary file upload in Request a Quote for WooCommerce (plugin path wp-content/plugins/woocommerce-request-a-quote/) ≤2.9.2. Handler afrfq_submit_quote_via_popup() passes attacker-controlled filename into move_uploaded_file() with no extension/MIME allowlist → .php into web-accessible RFQ temp storage when a public multi-page popup quote rule is enabled. AJAX: action=afrfq_submit_quote_via_popup via admin-ajax.php. Marketplace still listed 2.9.2 as current per Sep 26 reporting (no confirmed fixed release to install); public check/exploit PoC (murrez/CVE-2026-18143). No KEV / no confirmed ITW at disclosure — weaponization window is hours–days for this class.

What’s New:

  • Fresh Wordfence CVE + public Python PoC (check + upload-probe modes)
  • No patch on marketplace as of disclosure — config kill-switch is the fix today
  • Exact AJAX action + plugin path for DE hunts

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-18143 on Addify Request a Quote for WooCommerce ≤2.9.2 (woocommerce-request-a-quote); prerequisite: public quote rule with multi-page popup uploadVulnerable WooCommerce pluginT1190 / T1505.003Plugin inventory / WooCommerce.comDisable public popup quote rule or gate quotes behind login until fixed >2.9.2 ships; deny PHP execution under wp-content/uploads
POST to /wp-admin/admin-ajax.php with action=afrfq_submit_quote_via_popup + multipart file whose client filename ends .php / .phtml; follow-on GET to RFQ temp path under uploadsExploit probe / webshell dropT1190 / T1505.003Web / WAF / access logsAlert unauth POSTs to that action; block .php uploads; hunt new .php under wp-content/uploads and RFQ temp dirs since 2026-09-26
Plugin path /wp-content/plugins/woocommerce-request-a-quote/; FOFA/body markers afrfq / plugin path string; PoC repo github.com/murrez/CVE-2026-18143Inventory / PoCT1190Asset / code searchInventory installs; if popup public: treat as exposed; rotate WP/admin/DB secrets if unexpected PHP found

Detection

SourceRuleGap
Splunk ESCUNone — verified search for CVE-2026-18143 / afrfq_submit_quote_via_popup / woocommerce-request-a-quote. Existing WordPress Bricks Builder Plugin RCE is a different plugin — rejectedNo Addify RFQ analytic
ElasticPartial — Initial Access via File Upload Followed by GET Request (multipart Content-Disposition/filename= then GET/POST to uploaded script) would catch upload→execute sequence if HTTP body capture enabled. Partial — Unusual File Creation under Web Directories covers writes under */uploads/* by web processes. Rejected PHP File Creation in WordPress Plugin Directory — logic is */wp-content/plugins/* only; RFQ drops into uploads/temp, not pluginsNo CVE-2026-18143 / afrfq_* specific rule
SigmaNone — verified search for afrfq / CVE-2026-18143No emerging-threat rule

Hunt hint: (1) Find plugin ≤2.9.2. (2) Confirm whether public popup quote is on. (3) Grep access logs for afrfq_submit_quote_via_popup since 2026-09-26. (4) List new .php under uploads/RFQ temp; block PHP execution in uploads as defense-in-depth.

Sources: Suriq analysis, Freshy bulletin, Wordfence TI id 3417ec27…, PoC murrez/CVE-2026-18143, NVD CVE-2026-18143


3. Mini Shai-Hulud GitHub Actions Re-Enablement — actions-cool/*

TL;DR: Socket (2026-09-24, update 2026-09-25): GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled after the May 2026 Mini Shai-Hulud compromise, were re-enabled ~2026-09-16 09:09–16:16 UTC with malicious release tags intact. Tag refs (e.g. uses: actions-cool/[email protected]) resumed downloading payload commit a0c53dd42fc842d2f9276c5a1d4f9a26abe8713d (obfuscated index.js) → oven-sh/setup-bun + bun run $GITHUB_ACTION_PATH/index.js harvesting CI secrets. ~15k dependents on issues-helper alone. Both repos disabled again 2026-09-25 (workflows now fail at setup). Anyone who ran a tag ref during the window must rotate secrets and audit.

What’s New:

  • Containment regression: same May tags, no new malware publish required
  • Concrete malicious commit SHA + Bun runner IoCs for CI log hunts
  • Second disable confirms platform response; exposure window closed but secrets may already be burned

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Workflow refs actions-cool/issues-helper@* / actions-cool/maintain-one-comment@* by mutable tag (e.g. @v2.2.1); malicious resolve commit a0c53dd42fc842d2f9276c5a1d4f9a26abe8713dCompromised CI actionT1195.002 / T1552.github/workflows/ / Actions run historyRemove or pin to full SHA of a pre-2026-05-18 clean commit; never trust these tags
Runner logs: download oven-sh/setup-bun; command bun run $GITHUB_ACTION_PATH/index.js; jobs flipping from seconds-long “Repository access blocked” failures to multi-minute successes on/after 2026-09-16Execution / IoCT1059 / T1552.001GitHub Actions logsHunt runs 2026-09-16 → 2026-09-25; rotate every secret + review GITHUB_TOKEN scopes for those workflows
Historical Mini Shai-Hulud exfil domain t.m-kosche.com (May cluster overlap per Socket/THN); unexpected commits on dependent repos after 2026-09-16C2 / persistenceT1041 / T1195DNS / git historyBlock/monitor domain; audit unexpected commits/PRs since re-enable

Detection

SourceRuleGap
Splunk ESCUNone — verified search for actions-cool/issues-helper / Mini Shai-Hulud Actions re-enable. npm supply-chain stories exist but no analytic matching these action tagsNo GitHub Actions tag-compromise detection in local ESCU tree
ElasticNone for actions-cool tags. Related runners (Execution via GitHub Actions Runner, register-runner rules) cover self-hosted runner patterns — rejected as wrong class for hosted tag malwareNo rule for oven-sh/setup-bun inside issues-helper
SigmaPartial / rejected for this variant — Shai-Hulud ET rules (proc_creation_*_mal_shai_hulud_malicious_node_bun_execution) require bun_environment.js / npm Second Coming paths; Mini Actions uses bun run $GITHUB_ACTION_PATH/index.js. Workflow file rule only matches shai-hulud-workflow.yml filenames — not actions-coolNo ET rule for actions-cool re-enable; Bun rules wrong payload path

Hunt hint: (1) Org-wide code search actions-cool/issues-helper@ and maintain-one-comment@. (2) Actions history Sep 16–25 for duration jump + setup-bun. (3) Rotate secrets for any hit. (4) Pin all third-party actions to full commit SHAs going forward.

Sources: Socket blog, The Hacker News, BleepingComputer


Status Updates

  • CVE-2026-5430 (WSO2) / CVE-2026-71362 (Adobe Magento): KEV due TODAY 2026-09-27 (forensic triage Yes) — finish WSO2 update levels / Magento -2026-aug patches; keep JWT alg + editPost id= hunts. Sep 25
  • CVE-2026-65660 (SharePoint) / CVE-2026-67279 (MikroTik) / CVE-2026-87902 (WordPress): KEV due TOMORROW 2026-09-28 — SharePoint fixed builds / sphealth.aspx; RouterOS ≥6.49.21/≥7.23.4/≥7.24.2; WP ≥7.1.2 + pearcmd hunts. Covered Sep 26 staging · WP lead Sep 24 · MikroTrick Sep 06
  • CVE-2026-35273 (PeopleSoft UNC6240) / CVE-2026-48842 (Roundcube): No material change — keep /%50SEMHUB/ + SIDEEYE / Roundcube ≥1.6.16/≥1.7.1 hunts. Sep 26 staging
  • CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25 — confirm Eng HF / Jumbo / VCO ≥5.2.3.16|≥6.4.2.8 / sk1000117 / Artifactory + hunts. Sep 23 · Sep 12 · Sep 11
  • CVE-2026-61674 (Fluent Bit): No material change — agents ≥5.0.8. Sep 25
  • CVE-2026-63077 (TeamCity) / CVE-2026-80521 (Ubuntu AF_UNIX) / CVE-2026-32996 (Veeam) / CVE-2026-93485 (Comment2Shell): No material change — TeamCity ≥2025.11.7/≥2026.1.3, Veeam Agent 13.0.3.1220, WP Comment2Shell ≥7.1.1 (87902 still needs ≥7.1.2). Sep 24 · Sep 22