We made it through another weekend. Barely. If your phone didn’t ring on Saturday, you either don’t run Citrix or you slept through the CISA alert. Here is the weekend wrap of what broke while we were trying to log off.
The NetScaler PreAuth Nightmare
Citrix confirmed two critical NetScaler zero-days (CVE-2026-88771 and CVE-2026-88772) are actively being exploited in the wild.[1] Both are 9.5 CVSS pre-auth remote code execution flaws. The first one hits all NetScaler ADC and Gateway appliances on default configurations. The second requires DTLS, which is enabled by default on VPN virtual servers.[1]
CISA gave federal agencies until Wednesday to patch, which means the rest of us need to be done yesterday.[1] The mood over on the r/netsec boards is grim, with researchers dubbing it another instance of “the foot gun going off."[4] If you haven’t patched to the latest 14.1 or 13.1 builds, your perimeter is completely exposed. Drop everything and do it now.
Kiteworks Tells Everyone to Turn It Off
If you use Kiteworks for secure file sharing, you probably got a surreal email on Friday. They told customers worldwide to literally shut their servers down for a six-hour window on Saturday.[3]
They cited “credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems."[3] They claim it’s preventative and not a response to a confirmed breach, and that the current 9.5.1 release is safe.[3] A vendor telling me to turn off the product for a specific six-hour block isn’t great. Keep an eye on your logs if you run it.
Cloudflare’s Cross-Tenant Leak
Over on the cloud side, Cloudflare fixed a cross-tenant data exposure flaw in their Containers and Sandboxes.[2] If you had a Workers Paid account, a bug in how they reused 64 KiB storage blocks meant you could theoretically read residual data from other customers’ containers on the same host.[2]
The issue was a shared storage pool that skipped zeroing reused blocks. By writing just 4 KiB to an unused region, a new container could allocate a 64 KiB block and leave the remaining 60 KiB of the previous tenant’s data completely readable.[2] That includes .env files, databases, and filesystem metadata.[2] Cloudflare says they fixed the issue globally by September 19 and found no evidence of malicious exploitation.[2] It’s a reminder that “serverless” just means someone else’s shared server, and tenant isolation is only as strong as the block-zeroing script.
Sources
[1] https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days [2] https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/?source=newscura [3] https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks [4] https://www.reddit.com/r/netsec/comments/1wsbh8j/oh_look_the_foot_gun_went_off_again_citrix