News Room
16
Share
Critical Zero-Day Vulnerabilities Surge: FortiMail and Citrix NetScaler Under Active Exploitation
criticalZero-Day Exploits

Critical Zero-Day Vulnerabilities Surge: FortiMail and Citrix NetScaler Under Active Exploitation

A wave of critical zero-day vulnerabilities is impacting enterprise infrastructure, with CISA issuing urgent mandates for FortiMail and Citrix NetScaler. Threat actors are actively exploiting these flaws.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Critical Zero-Day Vulnerabilities Surge: FortiMail and Citrix NetScaler Under Active Exploitation for ₿ 0.10 BTC. Contact us.

06 October 2026Last updated 06 October 20264 min readBleepingComputer
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-104286, CVE-2026-88779, CVE-2026-88771
Source:
BleepingComputer
Read Time:
4 min

Executive Summary

In the last 72 hours, the cybersecurity landscape has been dominated by the active exploitation of critical zero-day vulnerabilities in widely deployed enterprise edge devices. Specifically, Fortinet’s FortiMail and Citrix NetScaler appliances have been targeted by sophisticated threat actors. CISA has responded by adding these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation for federal agencies.

Threat Analysis

The current threat environment shows a clear focus on perimeter security devices. By targeting appliances like FortiMail and NetScaler, attackers gain a foothold in the network, allowing for lateral movement, data exfiltration, and persistent access. The rapid succession of these disclosures suggests a coordinated effort by advanced persistent threat (APT) groups to capitalize on unpatched infrastructure before organizations can complete their patch cycles.

Technical Details

  • FortiMail (CVE-2026-104286): This critical vulnerability (CVSS 9.8) allows unauthenticated attackers to perform arbitrary file writes on the underlying system via crafted HTTP/HTTPS requests. It stems from path traversal and improper neutralization of NULL bytes.
  • Citrix NetScaler (CVE-2026-88779): A newly observed issue involving SAML authentication in customer-managed deployments. This follows recent RCE vulnerabilities (CVE-2026-88771/88772) that were also exploited in the wild, characterized by command injection and unauthorized superuser creation.

Attribution Assessment

While specific threat actor identities remain under investigation, the nature of these exploits—targeting high-value edge infrastructure—is consistent with state-sponsored espionage groups. The use of zero-days in these specific products suggests actors with significant resources for vulnerability research and exploit development.

Implications

Organizations relying on these technologies face a high risk of compromise. Successful exploitation allows for full system control, potentially leading to massive data breaches or the deployment of ransomware. The speed at which these vulnerabilities have moved from discovery to active exploitation leaves little room for delayed patching.

Recommendations

  1. Immediate Patching: Prioritize the installation of vendor-supplied security updates for all FortiMail and NetScaler instances.
  2. Forensic Triage: Conduct thorough audits of system logs for suspicious file modifications, unauthorized configuration changes, or anomalous authentication patterns.
  3. Network Segmentation: Isolate critical edge devices from internal networks where possible to limit the blast radius of a potential compromise.
  4. Monitor CISA KEV: Regularly check the CISA Known Exploited Vulnerabilities catalog for new entries and adhere to mandated remediation timelines.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo