Three widely deployed products went under confirmed exploitation in the last week of September, and in each the flaw sat in the component that authenticates users or configures other devices. In all three, attackers were working the flaw before the advisory existed, so the patching window and the exposure window are not the same period.
1
Two NetScaler zero-days exploited before Citrix disclosed them — CVE-2026-88771 and CVE-2026-88772
India exposureBoth rate 9.5 on CVSS v4. CVE-2026-88771 gives unauthenticated command execution in the default configuration of NetScaler ADC and Gateway; CVE-2026-88772 is a memory overflow reachable wherever DTLS is on, the default for VPN virtual servers. NetScaler Gateway fronts remote access for Indian banking, insurance and IT services. Unit 42 traced version fingerprinting to 21 August and web shell drops through September, before the advisory on 27 September.
ActionMove to 14.1-73.37 or 13.1-64.23, and 13.1-37.279 on the FIPS and NDcPP lines. Where that cannot be immediate, reduce internet exposure. Web shells survive the upgrade, so hunt for them separately and rotate what the appliance held.
SourceCitrix security bulletin, reported by BleepingComputer, 27 September 2026; Palo Alto Networks Unit 42, 30 September 2026; CISA Known Exploited Vulnerabilities catalogue, 27 September 2026.
2
Cisco Catalyst SD-WAN Manager hands administrator access to one crafted request — CVE-2026-76504
India exposureRated 9.8. The API mishandles URL encoding, so a crafted request skips the rule guarding a protected endpoint and returns administrator privileges. Configuration does not alter the exposure and Cisco lists no workaround. The controller holds configuration for every branch beneath it, which in India means multi-branch banks, NBFCs, retail chains and providers running customer networks.
ActionUpgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1. Take the management interface off untrusted networks and review administrator activity for the weeks before the fix.
SourceCisco security advisory, 30 September 2026; Rapid7, 30 September 2026; CISA KEV catalogue, 30 September 2026, remediation date 3 October 2026.
3
Microsoft documents a running campaign against Zimbra mail servers — CVE-2026-73570
India exposureUnauthenticated command injection in the SNMP notification path, triggered by a crafted email with no user interaction, where the optional zimbra-snmp package is installed and notifications are enabled. Commands run as the zimbra service account. Zimbra carries mail for many Indian government departments, public sector undertakings, state bodies and universities on self-managed servers. Microsoft records web shells, stolen credentials and authentication keys, and mailbox data staged for exfiltration.
ActionThe fix shipped in 10.1.20 on 20 July. Until it is applied, remove zimbra-snmp or disable SNMP notifications. Rotate Zimbra authentication secrets and search application directories for JSP web shells.
SourceMicrosoft Threat Intelligence, 30 September 2026; CISA KEV catalogue, 21 August 2026.
4
Chinese espionage cluster names India among eight countries targeted — UAT-11587
India exposureCisco Talos assessed with moderate to high confidence that the campaign reached government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria, with roughly 350 compromised endpoints. Antino, the backdoor, is compiled in Rust and takes its instructions from Outlook and OneDrive rather than attacker-registered infrastructure, so the command channel is ordinary Microsoft 365 traffic.
ActionEgress filtering will not separate this from legitimate use. Work from mailbox and OneDrive audit logs, unexpected Graph and EWS application activity, and execution of HTA, WSF and JScript files from user-writable paths.
SourceCisco Talos, 30 September 2026.
5
KillSec infrastructure seized in Europe while India leads the regional victim count
India exposureHamburg police, with Europol and Eurojust, took over KillSec's leak site on 30 September, securing at least 110 terabytes of stolen data along with five servers and five domains, and arresting three suspects in Spain, the United Kingdom and Romania. Investigators are examining about 1,000 suspected attacks. The group worked through software flaws and poorly secured cloud storage. Cyble separately reported that groups publicly claimed 24 Indian victims in August, the highest count in Asia-Pacific.
ActionOne operation has been removed, not the route it used. Audit cloud storage permissions, remote access without MFA, and the separation of backups from production credentials.
SourceEuropol and Hamburg police action, reported by The Hacker News, 1 October 2026; Cyble Research and Intelligence Labs, 30 September 2026. All three vulnerabilities above were exploited before the advisory that described them, and each gave the attacker reason to leave something behind: a web shell, a stolen key, a configuration already copied. Patching on advisory day answers the first question and not the second. The KillSec seizure makes the same point from the other direction, since the access those intrusions relied on was exposed storage and remote entry without MFA. — Nirad Threat Research