Cyber Threat Brief — September 27 2026
1. Citrix NetScaler Dual Unpatched RCE Zero-Days (ITW; CVE pending)
TL;DR: watchTowr (2026-09-26): two separate, unpatched remote code execution flaws in NetScaler ADC / NetScaler Gateway were exploited before any fix existed, discovered during forensic investigations. Distinct from KEV auth-bypass CVE-2026-19490 (patched 2026-08-19). Citrix has not published CVE IDs, affected builds, CVSS, workaround, or IoCs as of 2026-09-27; communications and patches expected early week of 2026-09-28. Field reports: private firmware via Sev1 support case; informal NCSC-NL / MSP shutdown advice (no new public NCSC advisory beyond NCSC-2026-0318 for 19489/19490). Treat internet-facing appliances as high risk — isolate or power off where ops allow; assume compromise if exposed during the ITW window.
What’s New:
- watchTowr confirmed two RCE 0-days + forensic ITW (not rumor-only); explicitly not CVE-2026-19490
- Admins taking appliances offline; private Sev1 build reported ahead of public bulletin
- No public IoCs — detection is inventory + compromise assessment, not signature matching
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Unpatched dual RCE on NetScaler ADC / NetScaler Gateway (CVE IDs pending; not CVE-2026-19490 / CVE-2026-19489 / CVE-2026-8452). Builds on Aug fixed train (14.1-73.32, 13.1-63.21) not confirmed safe by Citrix for the new flaws. 13.1 End of Maintenance 2026-09-15 — patch eligibility unclear | Vulnerable edge VPN/ADC / 0-day | T1190 | NetScaler inventory / Citrix support | Open Sev1 for private firmware; watch Citrix Security Bulletins; prefer isolate/power-off internet-facing VIP until public advisory |
Management plane internet exposure; crash dumps under /var/core (nsppe); remote syslog / NetScaler Console logs; VPX snapshot + tech support bundle | Forensic / exposure | T1190 / T1082 | NetScaler FS / syslog | Per Citrix suspected-compromise guidance: preserve evidence first, then isolate; keep Management Services off public internet; rotate service-account secrets, user passwords that authenticated through the appliance, and revoke certs/keys |
| NCSC-NL citrix-2025 compromise-check scripts (live host / core dump / disk image) — written for 2025 NetScaler ITW (e.g. CVE-2025-6543 class); not specific to these unpublished flaws | Hunt tooling | T1082 | Offline image / live appliance | Run as best-effort post-incident check (github.com/NCSC-NL/citrix-2025); negative result ≠ clean for the new 0-days |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for these unpublished 0-days. Prior Citrix analytics target different CVEs (CitrixBleed2 CVE-2025-5777 /p/u/doAuthentication.do; CitrixBleed CVE-2023-4966 OpenID config; CVE-2023-3519 VPN paths) — rejected as wrong vuln class | No HTTP/IoC signature exists publicly for the new pair |
| Elastic | None — verified search for NetScaler 2026 dual-RCE 0-day | No emerging-threat rule without CVE/IoC |
| Sigma | None — verified search (existing ET rules are CVE-2019-19781 / CVE-2020-8193 / CVE-2023-4966) | No rule for unpublished 2026 dual RCE |
Hunt hint: (1) Inventory all ADC/Gateway; note internet-facing AAA/Gateway VIPs. (2) Sev1 + isolate if exposed. (3) Preserve /var/core, remote syslog, Console logs before wipe/rebuild. (4) After private/public patch: still run compromise assessment — patch does not undo pre-patch foothold.
Sources: The Hacker News 2026-09-27, watchTowr Infosec.exchange, Cyber Kendra, THN X, NCSC-NL citrix-2025, Threadlinqs TL-2026-2682
2. Addify Request a Quote for WooCommerce Unauth PHP Upload — CVE-2026-18143
TL;DR: Wordfence-assigned CVE-2026-18143 (CVSS 9.8, CWE-434): unauthenticated arbitrary file upload in Request a Quote for WooCommerce (plugin path wp-content/plugins/woocommerce-request-a-quote/) ≤2.9.2. Handler afrfq_submit_quote_via_popup() passes attacker-controlled filename into move_uploaded_file() with no extension/MIME allowlist → .php into web-accessible RFQ temp storage when a public multi-page popup quote rule is enabled. AJAX: action=afrfq_submit_quote_via_popup via admin-ajax.php. Marketplace still listed 2.9.2 as current per Sep 26 reporting (no confirmed fixed release to install); public check/exploit PoC (murrez/CVE-2026-18143). No KEV / no confirmed ITW at disclosure — weaponization window is hours–days for this class.
What’s New:
- Fresh Wordfence CVE + public Python PoC (check + upload-probe modes)
- No patch on marketplace as of disclosure — config kill-switch is the fix today
- Exact AJAX action + plugin path for DE hunts
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
CVE-2026-18143 on Addify Request a Quote for WooCommerce ≤2.9.2 (woocommerce-request-a-quote); prerequisite: public quote rule with multi-page popup upload | Vulnerable WooCommerce plugin | T1190 / T1505.003 | Plugin inventory / WooCommerce.com | Disable public popup quote rule or gate quotes behind login until fixed >2.9.2 ships; deny PHP execution under wp-content/uploads |
POST to /wp-admin/admin-ajax.php with action=afrfq_submit_quote_via_popup + multipart file whose client filename ends .php / .phtml; follow-on GET to RFQ temp path under uploads | Exploit probe / webshell drop | T1190 / T1505.003 | Web / WAF / access logs | Alert unauth POSTs to that action; block .php uploads; hunt new .php under wp-content/uploads and RFQ temp dirs since 2026-09-26 |
Plugin path /wp-content/plugins/woocommerce-request-a-quote/; FOFA/body markers afrfq / plugin path string; PoC repo github.com/murrez/CVE-2026-18143 | Inventory / PoC | T1190 | Asset / code search | Inventory installs; if popup public: treat as exposed; rotate WP/admin/DB secrets if unexpected PHP found |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for CVE-2026-18143 / afrfq_submit_quote_via_popup / woocommerce-request-a-quote. Existing WordPress Bricks Builder Plugin RCE is a different plugin — rejected | No Addify RFQ analytic |
| Elastic | Partial — Initial Access via File Upload Followed by GET Request (multipart Content-Disposition/filename= then GET/POST to uploaded script) would catch upload→execute sequence if HTTP body capture enabled. Partial — Unusual File Creation under Web Directories covers writes under */uploads/* by web processes. Rejected PHP File Creation in WordPress Plugin Directory — logic is */wp-content/plugins/* only; RFQ drops into uploads/temp, not plugins | No CVE-2026-18143 / afrfq_* specific rule |
| Sigma | None — verified search for afrfq / CVE-2026-18143 | No emerging-threat rule |
Hunt hint: (1) Find plugin ≤2.9.2. (2) Confirm whether public popup quote is on. (3) Grep access logs for afrfq_submit_quote_via_popup since 2026-09-26. (4) List new .php under uploads/RFQ temp; block PHP execution in uploads as defense-in-depth.
Sources: Suriq analysis, Freshy bulletin, Wordfence TI id 3417ec27…, PoC murrez/CVE-2026-18143, NVD CVE-2026-18143
3. Mini Shai-Hulud GitHub Actions Re-Enablement — actions-cool/*
TL;DR: Socket (2026-09-24, update 2026-09-25): GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment, disabled after the May 2026 Mini Shai-Hulud compromise, were re-enabled ~2026-09-16 09:09–16:16 UTC with malicious release tags intact. Tag refs (e.g. uses: actions-cool/[email protected]) resumed downloading payload commit a0c53dd42fc842d2f9276c5a1d4f9a26abe8713d (obfuscated index.js) → oven-sh/setup-bun + bun run $GITHUB_ACTION_PATH/index.js harvesting CI secrets. ~15k dependents on issues-helper alone. Both repos disabled again 2026-09-25 (workflows now fail at setup). Anyone who ran a tag ref during the window must rotate secrets and audit.
What’s New:
- Containment regression: same May tags, no new malware publish required
- Concrete malicious commit SHA + Bun runner IoCs for CI log hunts
- Second disable confirms platform response; exposure window closed but secrets may already be burned
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
Workflow refs actions-cool/issues-helper@* / actions-cool/maintain-one-comment@* by mutable tag (e.g. @v2.2.1); malicious resolve commit a0c53dd42fc842d2f9276c5a1d4f9a26abe8713d | Compromised CI action | T1195.002 / T1552 | .github/workflows/ / Actions run history | Remove or pin to full SHA of a pre-2026-05-18 clean commit; never trust these tags |
Runner logs: download oven-sh/setup-bun; command bun run $GITHUB_ACTION_PATH/index.js; jobs flipping from seconds-long “Repository access blocked” failures to multi-minute successes on/after 2026-09-16 | Execution / IoC | T1059 / T1552.001 | GitHub Actions logs | Hunt runs 2026-09-16 → 2026-09-25; rotate every secret + review GITHUB_TOKEN scopes for those workflows |
Historical Mini Shai-Hulud exfil domain t.m-kosche.com (May cluster overlap per Socket/THN); unexpected commits on dependent repos after 2026-09-16 | C2 / persistence | T1041 / T1195 | DNS / git history | Block/monitor domain; audit unexpected commits/PRs since re-enable |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for actions-cool/issues-helper / Mini Shai-Hulud Actions re-enable. npm supply-chain stories exist but no analytic matching these action tags | No GitHub Actions tag-compromise detection in local ESCU tree |
| Elastic | None for actions-cool tags. Related runners (Execution via GitHub Actions Runner, register-runner rules) cover self-hosted runner patterns — rejected as wrong class for hosted tag malware | No rule for oven-sh/setup-bun inside issues-helper |
| Sigma | Partial / rejected for this variant — Shai-Hulud ET rules (proc_creation_*_mal_shai_hulud_malicious_node_bun_execution) require bun_environment.js / npm Second Coming paths; Mini Actions uses bun run $GITHUB_ACTION_PATH/index.js. Workflow file rule only matches shai-hulud-workflow.yml filenames — not actions-cool | No ET rule for actions-cool re-enable; Bun rules wrong payload path |
Hunt hint: (1) Org-wide code search actions-cool/issues-helper@ and maintain-one-comment@. (2) Actions history Sep 16–25 for duration jump + setup-bun. (3) Rotate secrets for any hit. (4) Pin all third-party actions to full commit SHAs going forward.
Sources: Socket blog, The Hacker News, BleepingComputer
Status Updates
- CVE-2026-5430 (WSO2) / CVE-2026-71362 (Adobe Magento): KEV due TODAY 2026-09-27 (forensic triage Yes) — finish WSO2 update levels / Magento -2026-aug patches; keep JWT
alg+editPost id=hunts. Sep 25 - CVE-2026-65660 (SharePoint) / CVE-2026-67279 (MikroTik) / CVE-2026-87902 (WordPress): KEV due TOMORROW 2026-09-28 — SharePoint fixed builds /
sphealth.aspx; RouterOS ≥6.49.21/≥7.23.4/≥7.24.2; WP ≥7.1.2 + pearcmd hunts. Covered Sep 26 staging · WP lead Sep 24 · MikroTrick Sep 06 - CVE-2026-35273 (PeopleSoft UNC6240) / CVE-2026-48842 (Roundcube): No material change — keep
/%50SEMHUB/+ SIDEEYE / Roundcube ≥1.6.16/≥1.7.1 hunts. Sep 26 staging - CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25 — confirm Eng HF / Jumbo / VCO ≥5.2.3.16|≥6.4.2.8 / sk1000117 / Artifactory + hunts. Sep 23 · Sep 12 · Sep 11
- CVE-2026-61674 (Fluent Bit): No material change — agents ≥5.0.8. Sep 25
- CVE-2026-63077 (TeamCity) / CVE-2026-80521 (Ubuntu AF_UNIX) / CVE-2026-32996 (Veeam) / CVE-2026-93485 (Comment2Shell): No material change — TeamCity ≥2025.11.7/≥2026.1.3, Veeam Agent 13.0.3.1220, WP Comment2Shell ≥7.1.1 (87902 still needs ≥7.1.2). Sep 24 · Sep 22