This Week’s CVE Priorities: Citrix, Check Point, F5, Cisco, and PeopleSoft Under Active Exploitation
By SAFE Threat Research Team
This week’s highest-priority vulnerabilities are concentrated across technologies that sit at critical enterprise trust boundaries, including application delivery, remote access, network management, and business applications. Citrix NetScaler, Check Point, F5 BIG-IP, Cisco SD-WAN Manager, and Oracle PeopleSoft all moved into focus because of active exploitation affecting systems with privileged access or broad operational reach.
The more important pattern is how that exploitation is evolving. Attackers are modifying request structures to bypass compensating controls, reverse-engineering security fixes to reproduce vulnerable code paths, and using compromised infrastructure for follow-on activity such as reconnaissance and persistence. The practical risk therefore depends not only on whether a vulnerability is being exploited, but on how much access and control the affected system can provide after successful exploitation.
Vulnerability Landscape
The disclosure volume remains substantial, with 3,239 CVEs published and 1,208 rated critical or high severity. At the time of writing, 8 had a public exploit or proof-of-concept available, while only 1 showed a weaponized exploit signal this week.

Trending Vulnerabilities
Thirteen CVEs showed confirmed exploitation activity this week, with nine involving previously known vulnerabilities and four involving newly published CVEs. The more relevant shift is within those individual cases: PeopleSoft exploitation returned with modified requests designed to bypass earlier WAF mitigations, Check Point disclosed both recent post-patch exploitation and earlier zero-day activity, while Cisco disclosed its SD-WAN vulnerability after already becoming aware of active exploitation.

Top CVEs to Watch
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Two Zero-Days Exploited Against Internet-Facing Appliances
Citrix disclosed eight vulnerabilities this week affecting NetScaler ADC and NetScaler Gateway, of which CVE-2026-88771 and CVE-2026-88772 stand out as both were exploited before patches became available. CVE-2026-88771 is an unauthenticated command-execution vulnerability caused by improper input validation and affects customer-managed NetScaler ADC and Gateway deployments without requiring a non-default configuration. CVE-2026-88772 is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, which is the default for VPN virtual servers.
Exploitation of CVE-2026-88772 dates back to at least early September and has affected organizations across government, financial services, technology, education, energy, and professional services. The activity abuses DTLS traffic to reach the NetScaler packet-processing path and establish root-level access, with post-exploitation activities including web shells and additional tooling to maintain persistence.
CVE-2026-88771 has followed a separate exploitation path. Observed requests delivered encoded shell commands that modified NetScaler HTTP configuration and deployed an internet-accessible web shell. With exploitation details now public, activity has expanded beyond the initial zero-day phase toward broader targeting of unpatched systems.
For affected NetScaler deployments, patching alone may be insufficient if the appliance was exposed during the exploitation window. Organizations should upgrade to a fixed release and assess previously exposed systems for signs of compromise.
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Adapts Exploitation to Bypass WAF Mitigations
CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools. Oracle released an out-of-band security update in June after the vulnerability had already been exploited as a zero-day, initially with significant targeting of higher-education environments.
The vulnerability has now entered a second, more mature exploitation phase. ShinyHunters-linked activity has resumed against unpatched systems and expanded into technology, IT services, healthcare, agriculture, transportation, government, and other sectors. Successful attacks have resulted in the deployment of web shells on compromised PeopleSoft servers.
More importantly, attackers adapted their exploit to bypass compensating controls deployed after the first campaign. Some organizations blocked the vulnerable /PSEMHUB/ path using WAF or reverse-proxy rules. The renewed activity used encoded path variations that bypassed literal-string matching while still being decoded and routed by PeopleSoft to the vulnerable servlet.
This makes CVE-2026-35273 particularly important from an exposure-management perspective. Signature-based compensating controls temporarily reduced exposure, but they did not eliminate the underlying vulnerability and were quickly bypassed once attackers adjusted their requests.
Check Point CVE-2026-85102 and CVE-2026-93616: Two Critical Flaws Move Into Active Exploitation
Check Point disclosed active exploitation of two critical vulnerabilities affecting its Security Gateway and Security Management products, bringing both into focus this week. CVE-2026-85102 is a pre-authentication remote code execution vulnerability in VPN certificate handling, while CVE-2026-93616 is a previously undisclosed pre-authentication path traversal vulnerability affecting the Security Management web service. Both are rated CVSS 9.8.
A patch for CVE-2026-85102 was released on September 9, with no exploitation known at the time of disclosure. Three days later, Check Point began observing a wave of exploitation attempts against Spark customers globally. The attacks used specially crafted certificate data during VPN negotiation and originated through anonymization infrastructure, including VPN services and proxies. Follow-on activity from suspicious Mobile Access sessions included internal port and service scanning, showing that successful exploitation was followed by reconnaissance against internal services.
CVE-2026-93616 was disclosed alongside that activity as a separate zero-day affecting the Security Management web service. The flaw allows an unauthenticated attacker to traverse paths, execute a script from an arbitrary location, and load an arbitrary Java class. Check Point identified a small number of targeted attacks exploiting the vulnerability on July 23, before defenders had a public CVE or patch available.
The significance this week, therefore, is the change in exploitation status. CVE-2026-85102 progressed to confirmed global exploitation within days, while CVE-2026-93616 was newly exposed as a zero-day that had already been used in targeted attacks. Organizations running affected Check Point gateways or management servers should treat the update as both a patching priority and a potential compromise-assessment requirement.
F5 BIG-IP APM CVE-2026-94127: Pre-Authentication RCE in an Identity-Aware Access Layer
CVE-2026-94127 is a critical heap-based buffer overflow affecting F5 BIG-IP Access Policy Manager. An unauthenticated remote attacker can send specially crafted traffic to an affected virtual server, potentially resulting in arbitrary code execution on the BIG-IP system.
The vulnerability does not affect every BIG-IP APM deployment. Exploitation requires a virtual server on which an APM access policy and an OAuth profile are configured together, effectively placing the vulnerable code path in environments that use BIG-IP as an OAuth authorization component. This configuration dependency narrows the exposed population but makes configuration-level exposure assessment essential.
F5 has confirmed exploitation in the wild, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities catalog.
The potential impact is significant because BIG-IP APM commonly sits directly in front of enterprise applications and identity-controlled resources. Successful exploitation, therefore, targets infrastructure responsible for mediating access into internal services rather than an isolated application workload.
Organizations should determine whether vulnerable BIG-IP versions meet the OAuth/APM configuration prerequisite, apply the relevant updates, and investigate affected virtual servers exposed externally for suspicious activity during the vulnerable period.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Authentication Bypass Reaches the Network Control Plane
CVE-2026-76504 is a critical authentication-bypass vulnerability in Cisco Catalyst SD-WAN Manager, publicly disclosed on September 30 after Cisco had already become aware of active exploitation. Improper handling of URI encoding in HTTP requests allows a remote, unauthenticated attacker to bypass an authentication rule that protects an API endpoint and gain access with administrative privileges.
There are no workarounds, and affected systems require an upgrade to a fixed release. The impact extends beyond the compromise of a single management application. Catalyst SD-WAN Manager operates as a centralized management and orchestration layer for distributed SD-WAN infrastructure. Administrative access can expose network topology, device configuration, and control mechanisms used across the environment.
Remediation should therefore be treated as both a patching and a compromise-assessment exercise. Organizations should preserve diagnostic data before upgrading and review affected Manager nodes for indicators of unauthorized administrative activity.
WordPress Core CVE-2026-87902: Security Fix Is Reverse-Engineered Within Hours
CVE-2026-87902 is a critical unauthenticated path traversal and local file inclusion vulnerability in WordPress Core, affecting versions from 4.7.0 through 7.1.1. The flaw exists in page-template resolution, where attacker-controlled input can cause WordPress to resolve a PHP file outside the expected theme directory.
Attack activity began almost immediately after the security update became available. Early requests closely matched the encoding behavior that the patch corrected, indicating that attackers had reverse-engineered the fix. Initial activity focused on verifying arbitrary file inclusion, but quickly progressed to attempts to include pearcmd.php and use it to write attacker-controlled PHP files to disk.
The distinction between the base vulnerability and the RCE chain is important. CVE-2026-87902 provides an unauthenticated local file inclusion primitive. Converting that into code execution depends on whether the target environment exposes a suitable PHP file or similar gadget. PEAR’s pearcmd.php is one observed route, but it is not universally present.
The vulnerability nevertheless moved rapidly from disclosure into repeatable exploitation and mass scanning. Its significance this week is therefore the speed with which attackers reverse-engineered the security fix and converted it into operational attack tooling.
What Security Teams Should Prioritize
- Treat affected Citrix NetScaler, Check Point, F5 BIG-IP, and Cisco SD-WAN systems as potential compromise cases where they were exposed before remediation.
- Patch Oracle PeopleSoft CVE-2026-35273 rather than relying on WAF or reverse-proxy rules that address only known exploit patterns.
- Review gateway and management-system telemetry for evidence of follow-on activity such as internal scanning, configuration changes, new files, web shells, or unauthorized administrative sessions.
- For WordPress CVE-2026-87902, assess both the vulnerable WordPress version and whether environmental components exist that can convert file inclusion into code execution.
- Preserve forensic evidence before upgrading affected infrastructure where exploitation may have occurred.
From Vulnerability Signal to Exposure Priority
This week’s CVEs show why exploitation evidence needs to be interpreted alongside the environment in which a vulnerability exists. The same CVE can represent very different risk depending on whether the affected asset is internet-facing, how critical the system is to the business, which security controls are in place, and whether exploitation has already been observed.
That distinction is especially relevant for this week’s set. A vulnerable NetScaler or Check Point gateway exposed to the internet demands a different response from a WordPress issue whose exploitability depends on the underlying PHP environment.
For security teams, the objective is therefore not simply to react to every newly exploited CVE, but to determine which vulnerabilities translate into meaningful exposure within their own environment.
SAFE CTEM brings together vulnerability intelligence, asset exposure, exploitability, security controls, and business context to help teams identify which vulnerabilities require attention first.