Cyber Threat Brief — September 28 2026
1. Citrix NetScaler dual RCEs patched and added to KEV — CVE-2026-88771 / CVE-2026-88772
TL;DR: Yesterday’s unpatched NetScaler zero-days now have public CVEs, fixed builds, and a CISA KEV due date of 2026-09-30. Preserve forensics, then patch to 14.1-73.37+ or 13.1-64.23+ and hunt the pre-auth path and community staging IoCs.
What’s New:
- Citrix CTX697096 assigned CVE-2026-88771 (unauth command injection, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow RCE/DoS, CVSS 9.5), plus siblings 88773–88778.
- Both RCEs are in the wild. CISA added them to KEV on 2026-09-27 (forensic triage: Yes).
- watchTowr published the pre-auth path and log-poison chain; Maurice_Sec shared suspected staging IoCs from a 2026-09-22 failed attempt.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-88771 / CVE-2026-88772 on NetScaler ADC/Gateway before 14.1-73.37 or before 13.1-64.23 (FIPS: before 14.1-73.37 FIPS / before 13.1-37.279). Distinct from CVE-2026-19490. | Vulnerable edge / KEV | T1190 | Inventory / show ns version | Preserve snapshot, support bundle, and /var/core before upgrade. Install the fixed build (use 13.1-64.24 if show ns variable returns vars). Rotate secrets and certs that traversed the appliance. Keep management off the public internet. Enable Enhanced ISN Generation for CVE-2026-88778 — upgrade alone does not fix it. |
POST /nf/auth/doAuthentication.do with login= containing pitboss, NSPPE, or shell metacharacters (; / backticks); delayed /netscaler/ns_monuploadd_err.pl | Exploit probe | T1190 / T1059 | NetScaler HTTP / syslog | Alert anomalous login strings. Hunt AAAD logs with pitboss or NSPPE; since 2026-09-22. Run NetScaler Console IOC scan (Console ≥14.1-73.36 + telemetry). A clean scan is not proof of clean. |
User-Agent prefix AA: + Base64; GET /logon/LogonPoint/custom/receiver.min.<hex>.css returning 404; webshell /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver; /bin/sh mode 6555 | ITW IoC (Maurice_Sec, suspected) | T1505.003 / T1222 | Access log / filesystem | Hunt AA: User-Agents and LogonPoint custom .css 404s. Check for .ctxs.receiver. Rebuild if compromised. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Existing CitrixBleed / doAuthentication analytics target different paths or vuln classes (*/p/u/doAuthentication.do*, CVE-2023-3519 / 4966). No rule for 88771 log-poison, AA: UA, or .ctxs.receiver. |
| Elastic | None — verified | No emerging-threat rule for these CVEs or IoCs. |
| Sigma | None — verified | Existing ET Citrix rules cover older paths only (/vpns/, CVE-2020-8193, CVE-2023-4966). |
Hunt hint: Inventory builds against 14.1-73.37 / 13.1-64.23. Preserve forensics, patch, then run Console IOC scan. Grep for AA: User-Agents, pitboss/NSPPE; in login fields, LogonPoint receiver.min.*.css, .ctxs.receiver, and /bin/sh mode 6555. KEV due 2026-09-30.
Sources: CTX697096 · CISA Alert · BleepingComputer · watchTowr Labs · watchTowr FAQ · THN on X · Maurice_Sec IoCs · murrez/CVE-2026-88772
2. Carbonato botnet — exposed Docker API to Hermes “GH0ST”
TL;DR: Carbonato worms hosts with an unauthenticated Docker API on TCP/2375, drops a privileged host-mounted container, and installs a Hermes Agent persona (GH0ST) that steals AI API keys. Close public 2375, then hunt the host paths and C2 list below — do not blanket-block legitimate hermes-agent.
What’s New:
- Full implant chain published (ThreatDown; THN amplify 2026-09-28): privileged create → host bind → reverse SSH → Hermes overwrite.
- C2 pattern is Telegram → LLM gateway → shell, not the older Hermes carding stories.
- Worm rescans the attached
/24every 5 minutes for more open Docker APIs.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
Unauthenticated Docker API on TCP/2375 creating privileged containers with Binds:["/:/host"] and nsenter -t 1. Image/repos: system/resolved, netd-svc, gh0st/*, fsociety/*. | Initial access / worm | T1190 / T1610 | Docker API / firewall | Inventory and block public 2375. Require auth on registries. Kill unexpected privileged containers. |
/root/.hermes/SOUL.md containing GH0ST; .env with CARBONATO_API_KEY; /usr/local/bin/.docker-network-monitor; miner path /usr/sbin/systemd-logind; process args [kworker/u2:0]; loot /root/.hermes/loot/ | Persistence / IoC | T1543 / T1036 / T1552 | Filesystem / process | Hunt and remove. Rotate AI API keys and SSH keys. Check immutable bits on cron/systemd/rc.local/OpenRC hooks. |
C2 IPs 45.79.183.61, 91.99.195.164, 213.136.79.115:8080 / :4444, LLM gateway 213.136.83.197, reverse tunnel 190.211.124.187 (AS262145); Telegram chat 750752697 / handle Carbo506 | C2 | T1071 / T1572 | Netflow / DNS | Block or monitor. Hunt reverse SSH ports derived from victim IP MD5. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Linux Suspicious Privileged Container Execution | Catches local docker run --privileged / --pid=host. Misses remote HTTP API creates on :2375 with no local docker CLI. No Carbonato / GH0ST / SOUL.md analytic. |
| Elastic | Partial — Privileged Container Creation with Host Directory Mount and Privileged Docker Container Creation | Cover privileged + host-mount when the endpoint sees runtime exec. Writable-docker-socket rules alone do not cover internet :2375. No Telegram / GH0ST / CARBONATO_API_KEY rule. |
| Sigma | None — verified | No ET rule for Carbonato / GH0ST / Hermes SOUL.md. |
Hunt hint: Scan for open 2375. Grep hosts for GH0ST in /root/.hermes/SOUL.md and CARBONATO_API_KEY. Check netflow to the listed IPs and AS262145. Rotate AI provider keys on any hit.
Sources: ThreatDown Carbonato · The Hacker News · BleepingComputer
3. Elementor CSRF can create a WordPress admin — CVE-2026-62062
TL;DR: A CSRF bug in Elementor 4.3.0–4.3.1 lets an attacker trick a logged-in admin into creating a new administrator via a crafted link. Upgrade to ≥4.3.2 and hunt access logs for elementor/v1/events/.
What’s New:
- CVE assigned (2026-09-25); Elementor shipped 4.3.2 (~2026-09-24). About 2M installs on the vulnerable pair.
- Bypass string
elementor/v1/events/is concrete enough for WAF and access-log hunts. - One-click via email, chat, or comment — no attacker-hosted page or JS required. No KEV and no confirmed ITW at briefing time.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
CVE-2026-62062 on wp-content/plugins/elementor/ versions 4.3.0 and 4.3.1; fixed in ≥4.3.2 | Vulnerable WP plugin | T1189 / T1098 | Plugin inventory | Upgrade free Elementor (and Pro stacks that use free core) to ≥4.3.2 immediately. |
Request URI containing elementor/v1/events/ plus REST routes that create users (e.g. /wp-json/wp/v2/users) while an admin session cookie is present | Exploit probe | T1189 / T1098 | WAF / access / WP audit | Alert on elementor/v1/events/. Review new admin users since 2026-09-22. Force-logout all admins after patch. |
| Tracker abraxas/CVE-2026-62062; Patchstack Elementor CSRF advisory | Inventory / PoC | T1189 | Code search | Inventory 4.3.0/4.3.1. Treat as exposed until 4.3.2+. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | No Elementor CSRF analytic. Existing Bricks Builder RCE rule is a different plugin. |
| Elastic | None — verified | No rule for elementor/v1/events/ CSRF. |
| Sigma | None — verified | No ET rule. |
Hunt hint: Find Elementor 4.3.0 / 4.3.1. Patch to ≥4.3.2. Grep access logs for elementor/v1/events/ since 2026-09-22. Audit wp_users for unexpected administrators and rotate admin sessions.
Sources: Tenable CVE-2026-62062 · BleepingComputer · Patchstack · abraxas/CVE-2026-62062
Status Updates
- CVE-2026-65660 (SharePoint): KEV due today (2026-09-28, forensic triage Yes). Confirm fixed builds /
sphealth.aspx. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due today. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due today (forensic triage Yes). Confirm WP ≥7.1.2 and keep pearcmd hunts. Sep 24 brief.
- CVE-2026-5430 (WSO2) / CVE-2026-71362 (Adobe Magento): KEV due was 2026-09-27. Confirm remediation; keep JWT
algandeditPost id=hunts. Sep 25 brief. - CVE-2026-18143 (WooCommerce RFQ) / Mini Shai-Hulud (
actions-cool/*): No material change. Keepafrfq_submit_quote_via_popupand secret rotation for Sep 16–25 tag-ref runs. Sep 27 brief. - CVE-2026-35273 (PeopleSoft / UNC6240) / CVE-2026-48842 (Roundcube): No material change. Keep
/%50SEMHUB/+ SIDEEYE hunts; Roundcube ≥1.6.16 / ≥1.7.1. Sep 26 brief. - CVE-2026-94127 (F5) / CVE-2026-93616 (Check Point Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25. Confirm Eng HF / Jumbo / VCO / sk1000117 / Artifactory. Sep 23 · Sep 12 · Sep 11.