Overview
Citrix has released a new security bulletin that addresses a new actively exploited, high severity vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. If the memory buffer vulnerability is successfully exploited, then a denial of service could occur.
- CVE-2026-88779 – Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability – CVSSv4.0 Score: 8.7
Affected Versions:
- NetScaler ADC and NetScaler Gateway: all versions before 14.1-73.41
- NetScaler ADC and NetScaler Gateway: all versions before 13.1-64.28
- NetScaler ADC 14.1-FIPS: all versions before 14.1-73.41 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: all versions before 13.1.37.282
Fortinet has released a security advisory addressing an actively exploited, critical vulnerability affecting their email security product, FortiMail. If the vulnerability is successfully exploited, then this may grant the unauthenticated attack the ability to write arbitrary files on the underlying system via HTTP / HTTPS requests.
- CVE-2026-104286 – Path Traversal Vulnerability – CVSSv3.1 Score: 9.8
Affected Versions:
- FortiMail 8.0.0 through to 8.0.1
- FortiMail 7.6.0 through to 7.6.6
- FortiMail 7.4.0 through to 7.4.8
- FortiMail 7.2.0 through to 7.2.9
Apple has released three security documents addressing a recent actively exploited, high severity vulnerability for Apple iOS and macOS products. Successful exploitation of this vulnerability can lead to execution of arbitrary code on the device.
- CVE-2026-86950 – Out-of-Bounds Write Vulnerability – CVSSv3.1 Score: 8.8
Affected Versions:
- iOS, iPadOS, macOS Tahoe & Sequoia: all versions before iOS 27
Cisco has released a security advisory addressing a recent actively exploited, critical vulnerability within the Cisco Catalyst SD-WAN Manager. If the hex encoding vulnerability is successfully exploited, then an unauthenticated, remote attacker could access the affected system with administrator privileges.
- CVE-2026-76504 – Hex Encoding Vulnerability – CVSSv3.1 Score: 9.8
Affected Versions:
- Cisco Catalyst SD-WAN:
- 20.9 until 20.9.10.1
- 20.12 until 20.12.8.2
- 20.15 until 20.15.6.1
- 20.18 until 20.18.4.1
- 26.1 until 26.1.2.1
- 26.2 until 26.2.1
Recommended Action
Organisations are encouraged to review the appropriate security advisory pages and apply the updates:
Citrix: CITRIX | Security Bulletin
Fortinet: Fortinet | FortiGuard Security Advisory
Apple: iOS & iPadOS Support , macOS Tahoe Support , macOS Sequoia Support
Cisco: Cisco Security Advisory