Skip to content
THREATWIRE

Intelligence

Threats

Campaigns, malware, and ransomware. A leak-site post is a claim until a better source confirms the impact.

Critical

Threats

The Gitea diffpatch bug is listed by CISA

CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.

Published 2m ago

Critical

Threats

NetScaler command execution is CVE-2026-88771

Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.

Published 2m ago

High

Threats

NetScaler SAML memory overflow is being exploited

CVE-2026-88779 is in the CISA KEV catalog. Citrix limits it to SAML service-provider or identity-provider configurations and describes denial of service. Earlier NetScaler fixes do not close it.

Published 1h ago

Threats

Reading ransomware claims without amplifying them

A leak-site post is a claim. Victim impact, data theft, and encryption are separate facts and stay unmarked until a better source exists.

Published 2d ago