# KLM Innovation Security Monitor **Date:** September 28, 2026 > Informational security guidance. Not certification. Not a substitute for scoped human review. ## Executive Summary Citrix confirmed and patched the two NetScaler RCE zero-days that were under active exploitation with no CVE and no fix as of yesterday, and CISA added both to KEV with a federal deadline of September 30. The patch is available, but the window for post-exploitation cleanup is open now, because the flaws were exploited before any fix existed and no public open IoC list has been published (check NetScaler Console for Citrix-provided IoCs). Simultaneously, ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 using a new URL-encoding trick that bypasses WAF rules that organizations deployed as a mitigation, deploying web shells and the SIDEEYE backdoor on dozens of systems across higher education, healthcare, government, and technology sectors. The operational imperative: patch NetScaler ADC and Gateway to 14.1-73.37 or 13.1-64.23 immediately and run forensic review in parallel, because the patch doesn't remove prior access. If you run PeopleSoft, the WAF mitigation is no longer sufficient. Patch, disable PSEMHUB, and hunt for web shells and SIDEEYE in WebLogic access logs. ## Founder Take WAF bypasses aren't a surprise. Pattern-matching rules are a blacklist, and attackers have been encoding around them for years. Treat the PeopleSoft wave as a three-control playbook: (1) patch the system itself (PeopleSoft / PSEMHUB here), (2) keep the WAF as a runtime defense layer but expect rule bypasses such as URL encoding, and (3) monitor continuously for evasions, including web shells and known backdoors from this campaign (SIDEEYE credential theft / reverse shell, Neo-reGeorg tunneling). ## Headline Developments ### 1. Citrix confirms and patches two NetScaler RCE zero-days, CISA adds both to KEV (CRITICAL) **Source:** [BleepingComputer](https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/) (Sept 27). Also [CISA NetScaler alert](https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway) and [CISA KEV add](https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog). Soft: [watchTowr FAQ](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/) secondary echo. - Citrix published security bulletin CTX697096 on September 27, confirming that CVE-2026-88771 (improper input validation, CVSS 9.5, unauthenticated RCE affecting all NetScaler ADC and Gateway deployments including default configuration) and CVE-2026-88772 (memory overflow, CVSS 9.5, exploitable when DTLS is enabled, which is on by default for VPN virtual servers) are being exploited in the wild. - Citrix released fixes: NetScaler ADC and Gateway 14.1-73.37, 13.1-64.23, FIPS 14.1-73.37, and NDcPP 13.1-37.279. The bulletin also fixes six additional NetScaler vulnerabilities, bringing the total to eight flaws addressed in this update. - CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 27. The federal civilian executive branch deadline under BOD 26-04 is September 30. - The Dutch NCSC-NL sent a pre-disclosure warning to organizations in the Netherlands before the public bulletin, citing information from a European partner CERT. The notice said one vulnerability allowed shellcode placement directly into memory, and that Citrix submitted a notification under the EU Cyber Resilience Act after discovering active exploitation at multiple customer sites worldwide. - No public open IoC list has been published for either flaw. Check NetScaler Console for Citrix-provided IoCs and run forensic triage per CISA/Citrix guidance. Do not invent hunt strings beyond vendor/CISA guidance. The NCSC-NL warned that exploitation attempts could increase once Citrix released patches and technical details. **Why this matters:** This resolves the most urgent item from the past 48 hours. Yesterday's brief flagged the NetScaler zero-days as the worst possible combination: active exploitation, no patch, no public IoCs. That combination has now changed to the second-worst: active exploitation, patch available, still no public open IoC list (Console IoCs may exist). The patch is the correct action, but it isn't the complete action, because an attacker who already got in before the patch will retain access after it. The defensive action is now two-step: patch immediately, then run forensic review in parallel. The NCSC-NL pre-disclosure warning is a new pattern worth tracking: national CERTs are now sharing zero-day intelligence with their own constituency before the vendor publishes, which means the warning window for defenders in other jurisdictions may be shorter. **Pattern callout:** Extends the "exploited flaws move to KEV and stay exploited" pattern (09-17 through 09-28). The SharePoint and MikroTik KEV additions (09-25/09-26) had patches at the time of KEV addition. The NetScaler additions did not. This is the third tier of the pattern: unpatched zero-days exploited before any fix, now resolved with a patch but without a public open IoC list. The pattern now covers the full lifecycle: zero-day, exploitation, vendor confirmation, patch, KEV, and the residual post-patch forensic gap. ### 2. ShinyHunters bypasses WAF to resume PeopleSoft CVE-2026-35273 exploitation, deploys SIDEEYE backdoor (HIGH) **Source:** [BleepingComputer](https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/) (Sept 27). Also [Google Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft). Soft: ShinyHunters FBI Jobs claim remains unconfirmed by the FBI (investigation acknowledged only). - Google Mandiant and GTIG reported that ShinyHunters (UNC6240) modified its exploit to bypass WAF rules that block the vulnerable `/PSEMHUB/` endpoint by using URL-encoded variants such as `/%50SEMHUB/`. Many WAFs and reverse proxies compare the literal request path before decoding, so rules matching `/PSEMHUB/` miss the encoded version. Oracle WebLogic decodes the path and routes it to the vulnerable handler. - The new wave of attacks has deployed web shells on dozens of systems worldwide across higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors. - The attack sequence: five to 15 POST requests to `/%50SEMHUB/hub` containing serialized Java objects (recon), then command execution or JSP web shell deployment. The deployed artifacts include `x.jsp` (command execution), `u.jsp`/`u2.jsp` (file upload), and on Windows servers `Ple64.exe`, a masquerading signed installer that drops the SIDEEYE backdoor. - SIDEEYE capabilities include credential theft, process and file management, interactive reverse shells, and reverse proxy functionality. The group also deployed the Neo-reGeorg tunneling toolkit via `tunnel.jsp`/`tunnel.jspx` for SOCKS5 proxy traffic over HTTP/HTTPS to spread laterally into internal networks. On Linux systems, MeshAgent remote management software was used to maintain access. - This follows ShinyHunters' September 22 claim of using the same PSEMHUB component to breach the FBI Jobs platform and access FBI AWS GovCloud infrastructure, claiming 2TB to 3TB of data theft. The FBI confirmed it was investigating the claim but didn't confirm a breach. ShinyHunters confirmed to BleepingComputer that it used the WAF bypass against FBI Jobs. - Mandiant advises organizations to install the Oracle security update rather than rely on WAF rules, disable the Environment Management Hub where appropriate, and search WebLogic access logs for `/PSEMHUB/`, encoded variants, suspicious POST requests to `/hub`, and unexpected JSP requests. **Why this matters:** This is a concrete demonstration that a WAF-based mitigation for a known exploited CVE isn't a durable control. The attacker adapted the exploit in under three months (June 10 initial exploitation, September 27 new WAF bypass wave), and the adaptation cost the attacker nothing but a different URL encoding. For defenders who deployed WAF rules as a stopgap instead of patching, the mitigation has now been invalidated. The SIDEEYE backdoor and Neo-reGeorg lateral movement toolkit mean that a compromised PeopleSoft server isn't just a data-theft endpoint; it's a pivot point into the internal network. The operational action is clear: patch, disable PSEMHUB, hunt for the known web shell artifacts, and treat any server that matched the WAF rule as potentially already compromised. **Pattern callout:** Extends the "the credential is still the breach" pattern (09-13 through 09-28) at the infrastructure layer. The PeopleSoft flaw is unauthenticated RCE, meaning the attacker doesn't need credentials to get in. The WAF bypass shows that the defensive boundary (the WAF rule) is the thing being defeated, not the authentication layer. This is the same failure mode as the NetScaler zero-days (09-27/09-28): the edge appliance is the boundary, and the boundary is failing. The difference is that PeopleSoft has a patch and known artifacts to hunt for; NetScaler still lacks a public open IoC list (check Console for Citrix-provided IoCs). ## Pattern Analysis **Pattern 1: Exploited flaws move to KEV and stay exploited (09-17 through 09-28, 12 days running).** Cisco ISE and SEG (09-20/09-21), the two Microsoft EoP zero-days (09-20), Zyxel GS1900 CVE-2026-7273 (09-21, deadline 09-24), WSO2 API Manager CVE-2026-5430 (09-24, deadline 09-27), SharePoint CVE-2026-65660 and MikroTik CVE-2026-67279 (09-25, deadlines 09-28 for SharePoint and for MikroTik 67279), and now Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (09-27, deadline 09-30) are all in KEV within a two-week window. The NetScaler additions are the third tier: unpatched zero-days exploited before any fix, now resolved with a patch but without a public open IoC list. The PeopleSoft WAF bypass (09-27) is the fourth dimension: a known exploited CVE where the deployed mitigation (WAF rule) has been defeated by a trivial attacker adaptation. The pattern isn't one bad month. It's the new baseline: active exploitation of enterprise infrastructure is a weekly occurrence, and the patching backlog is growing with it. **Pattern 2: The edge appliance is the boundary, and the boundary is failing (09-17 through 09-28).** The NetScaler zero-days (09-27/09-28), SharePoint RCE (09-25/09-28), MikroTik RouterOS admin takeover (09-25/09-28), WSO2 API Manager auth bypass (09-25/09-28), and now the PeopleSoft PSEMHUB WAF bypass (09-27/09-28) are all in the same category: the edge layer (load balancer, reverse proxy, API gateway, web server) is the attack surface. The WAF bypass adds a new failure mode: the defensive control itself (the WAF rule) is the thing being defeated, not the underlying authentication or access control. The defensive implication is that WAF-based mitigations aren't a substitute for patching, and the window between mitigation deployment and mitigation defeat can be as short as three months. **Pattern 3: The vendor is now the case study (09-16 through 09-28, 13 days running).** The OpenAI U.S. government website disclosure (09-26), the OpenAI/Hugging Face agent chain detail (09-26/09-27), and the OpenAI self-replicating prompt injection disclosure (09-25/09-27) all point at the same question: who is responsible when the agent causes the breach. The Citrix NetScaler confirmation (09-27/09-28) adds a new dimension to the pattern: the vendor's own discovery process (investigating customer incidents) is now the primary source of zero-day intelligence, and the NCSC-NL pre-disclosure warning shows that national CERTs are sharing this intelligence with their constituency before the vendor publishes. The defensive implication is that the warning window for defenders outside the CERT's constituency may be shorter than the vendor's public advisory suggests. **Pattern 4: The agent's supply chain is the supply chain (09-13 through 09-28, 16 days running).** LiteLLM CVE-2026-59822 (09-17), Orkes Conductor RCE CVE-2026-58138 (09-18), Plugin4Shell (09-19), MaxKB CVE-2026-77521 (09-21/09-22), FakeGit distribution campaign (09-23), Next.js/Satori CVE-2026-94545 (09-23/09-24), ServiceNow AI Platform unauthenticated flaws (09-24/09-25), SalesBleed in Salesforce Agentforce (09-25), and the Wallarm 2026 API ThreatStats report (09-26/09-27) all point at the same architectural assumption: the tool interface and API layer are trusted boundaries. They aren't. The PeopleSoft WAF bypass (09-27/09-28) is the infrastructure-layer confirmation: the API endpoint is the breach surface, and the WAF rule isn't a durable control. **Pattern 5: Regulatory and legal posture continues to tighten (09-14 through 09-28, 15 days running).** AEPD first AI-agent-attributed breach notification (09-16), CISA Zyxel deadline (09-21), Australia government investigation and vendor-notification rebuke (09-24), NIST SP 800-82 Rev 4 draft (09-24), CISA/FBI ICS integrator fact sheet (09-24), Forbes Council framing shift to agent-behavior-level monitoring (09-24), the OpenAI U.S. government website disclosure (09-26), and now the CISA KEV additions for NetScaler (09-27, deadline 09-30) and the NCSC-NL pre-disclosure warning (09-27) all move in the same direction. The NCSC-NL warning is a new data point: national CERTs are now sharing zero-day intelligence before vendor disclosure, which means the compliance window for non-Dutch defenders may be shorter than the public advisory suggests. The cost of treating agent and infrastructure security as an engineering problem instead of a compliance program is rising. ## Recommended Actions **Immediate (this week):** 1. **Patch Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772) immediately.** Citrix confirmed both flaws and released fixes in bulletin CTX697096 on September 27. CISA added both to KEV the same day with a federal deadline of September 30. Upgrade to 14.1-73.37, 13.1-64.23, FIPS 14.1-73.37, or NDcPP 13.1-37.279. The patch doesn't remove prior access: both flaws were exploited as zero-days before any fix existed, and no public open IoC list has been published. Check NetScaler Console for Citrix-provided IoCs; when compromise is suspected, preserve evidence before patching. Run forensic review in parallel: review NetScaler logs for unauthenticated access attempts, check for unexpected processes or configuration changes, and preserve evidence (VPX snapshot, remote syslog, technical support bundle, core dump). If you can't patch immediately, reduce Internet exposure where operationally possible. 2. **If you run Oracle PeopleSoft, patch CVE-2026-35273 and disable the Environment Management Hub.** ShinyHunters is actively exploiting the flaw using a URL-encoding WAF bypass. If you deployed WAF rules as a mitigation, they aren't sufficient anymore. Install the latest Oracle security update, disable PSEMHUB where appropriate, or remove the PSEMHUB application in single-server setups following Oracle's guidance. Search WebLogic access logs for `/PSEMHUB/`, encoded variants such as `/%50SEMHUB/`, suspicious POST requests to `/hub`, and unexpected JSP requests. Hunt for the known web shell artifacts: `x.jsp`, `u.jsp`, `u2.jsp`, `tunnel.jsp`, `tunnel.jspx`, and on Windows servers `Ple64.exe` (SIDEEYE backdoor). Treat any server that matched the WAF rule as potentially already compromised. 3. **Patch MikroTik RouterOS (CVE-2026-67279 + CVE-2026-86060) if not already done.** CVE-2026-67279 CISA deadline is today (September 28); CVE-2026-86060 deadline passed September 13. The MikroTrick chain results in full unauthenticated administrative console access on internet-exposed RouterOS 7.x devices. If you haven't patched, apply the patch now and review access logs for unauthenticated admin console access. 4. **Patch SharePoint Server (CVE-2026-65660) if not already done.** The CISA deadline was today (September 28). Microsoft confirmed reliable evidence of observed attacks. A public exploit exists. If you run on-premises SharePoint Server 2016, 2019, or Subscription Edition below the fixed build, apply the patch and review web server logs for unauthorized code execution. **This month:** 5. **If you deploy agents with access to email, file systems, or code repositories, add detection for self-replicating prompt injection patterns.** The OpenAI GPT-Red disclosure (09-25/09-27) documents the replication vectors: email, file system writes, and code comments. Audit for anomalous replication patterns in agent-generated content, and restrict agent egress to the minimum required. 6. **If you run JFrog Artifactory, apply the 7.161.15 or 7.146.34 fix.** The OpenAI/Hugging Face agent chain (09-26/09-27) exploited CVE-2026-65617 and related Artifactory CVEs. JFrog has shipped fixes. CISA added the exploited CVEs to its KEV catalog. If you run Artifactory below these versions, patch now. 7. **If you run LiteLLM or OpenClaw, apply the Anthropic threat intelligence report controls.** The September 2026 report (09-25/09-26) specifically calls out prompt injection of LiteLLM and OpenClaw deployments as an observed attack vector. If you run either tool, review your prompt injection defenses and restrict the agent's access to sensitive data. **Ongoing:** 8. **Build the agent-incident disclosure path now, not after the first breach.** The Australia government investigation (09-24) shows that a two-month notification delay is a sovereign-level failure. The OpenAI U.S. government website disclosure (09-26) and the OpenAI/Hugging Face agent chain (09-26/09-27) show that the pattern is now affecting federal agencies at scale. The organizations that will be in a better position when the first enforcement action lands are the ones that already have a tested disclosure path for AI-caused incidents. 9. **Adopt the agent-behavior-level monitoring framework.** The Forbes Council post (09-24) frames the shift: log not just the API call but the context, the sequence, and the deviation from the authorized objective. The OpenAI/Hugging Face agent chain (09-26/09-27) and the self-replicating prompt injection disclosure (09-25/09-27) provide concrete examples of the failure modes to monitor for: multi-agent coordination via shared infrastructure, DNS tunneling, and self-replicating injection propagation. If you're building agent deployments, this is the design principle to adopt now. 10. **Review the NIST SP 800-82 Rev 4 draft before the November 30 comment deadline.** The draft is the window to influence the final document. The OpenAI/Hugging Face agent chain (09-26/09-27) and the self-replicating prompt injection disclosure (09-25/09-27) are both relevant to the agent-behavior-level monitoring framework that the draft is building toward. ## Relevant Risk Summary | Risk | Severity | Recommended Actions | |---|---|---| | Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (RCE, unauthenticated) exploited as zero-days, patch available, no public open IoC list (check Console) | CRITICAL | Patch to 14.1-73.37 / 13.1-64.23 immediately (KEV due Sep 30); check NetScaler Console IoCs; run forensic review in parallel; preserve evidence; reduce Internet exposure if patching is delayed | | Oracle PeopleSoft CVE-2026-35273 (unauthenticated RCE) WAF bypass by ShinyHunters, web shells and SIDEEYE deployed on dozens of systems | HIGH | Patch Oracle PeopleSoft; disable PSEMHUB; hunt for x.jsp, u.jsp, Ple64.exe, tunnel.jsp artifacts; review WebLogic access logs for /PSEMHUB/ and encoded variants | | MikroTik RouterOS CVE-2026-67279 (KEV due 09-28 today) + CVE-2026-86060 (KEV due 09-13, overdue) | HIGH | Patch RouterOS 7.x now; review access logs for unauthenticated admin console access | | SharePoint CVE-2026-65660 (RCE) KEV, deadline 09-28 (today) | HIGH | Patch SharePoint Server 2016/2019/Subscription Edition now; review web server logs for unauthorized code execution | ## Sources - [BleepingComputer - Citrix confirms two NetScaler RCE zero-days exploited in attacks](https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/) - [CISA - Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway](https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway) - [CISA - CISA Adds Two Known Exploited Vulnerabilities to Catalog](https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog) - [BleepingComputer - ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks](https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/) - [Google Threat Intelligence - ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft) - [watchTowr - Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/) *Generated: 2026-09-28 07:30 EDT | Window: past 24h | Sources: BleepingComputer, CISA, Google Threat Intelligence, watchTowr*