Opens in a new tab

Security Roundup, October 3: Citrix NetScaler Zero-Days and GitLab AI Gateway RCE

  • Home
  • Blog
  • Security Roundup, October 3: Citrix NetScaler Zero-Days and GitLab AI Gateway RCE
Security roundup October 3 illustrated by a hand pulling a server rack breaker switch

IT and security teams gained clear, actionable insight this week as two widely deployed enterprise platforms faced active exploitation. Citrix NetScaler saw two zero-day vulnerabilities hit by attackers in the wild, and GitLab disclosed a critical remote code execution flaw in its self-hosted AI Gateway service. Both require immediate patching across affected environments, joined by new CISA Known Exploited Vulnerabilities, Dell Container Storage Module flaws, a Frontline Education breach, and ongoing Warlock ransomware activity targeting critical infrastructure.

Citrix NetScaler Zero-Days Under Widespread Exploitation

On September 24, threat detection firm GreyNoise Intelligence observed a single US-based IP address scanning for Citrix NetScaler installations and conducting remote code execution attacks. The company issued alerts to customers about the malicious activity. Over the next two days, reports of potential zero-day attacks on NetScaler installations emerged on social media, and cybersecurity professionals debated whether the rumored attacks were real, with some arguing the activity targeted vulnerabilities already patched in August.

On September 26, an exposure-management firm urged NetScaler users to take their systems offline, warning that the following Monday would be too late. By Sunday, Citrix posted an update patching eight vulnerabilities, tracked as CVE-2026-88771 through CVE-2026-88778, including two zero-days that had been exploited in the wild. The post urged customers to upgrade to the versions containing the fix immediately. The two zero-days, CVE-2026-88771 and CVE-2026-88772, came under widespread exploitation shortly after disclosure.

What to do now: identify every Citrix NetScaler ADC and NetScaler Gateway instance on the network, apply the patched versions from the September 27 bulletin, and audit for indicators of compromise dating back to at least September 24. Any appliance that cannot be patched within the next 24 hours should be isolated or taken offline until it can.

GitLab AI Gateway Critical RCE (CVE-2026-90970)

GitLab warned customers on October 2 to patch a critical vulnerability in its AI Gateway service that could let attackers run arbitrary commands on vulnerable instances. AI Gateway gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based instance for GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted AI Gateway through GitLab Duo Self-Hosted.

Tracked as CVE-2026-90970, the flaw stems from an improper neutralization weakness. Attackers with basic privileges and Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue for self-hosted AI Gateway users. Customers using a GitLab-hosted AI Gateway are already protected and do not need to take action.

What to do now: every GitLab Self-Managed deployment running a self-hosted AI Gateway should upgrade immediately to 19.2.4, 19.3.2, or 19.4.1. Review Duo Agent Platform access lists and revoke any unnecessary user privileges on the Gateway while the upgrade window is open.

CISA Adds Two Known Exploited Vulnerabilities to the KEV Catalog

On October 2, CISA added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, the authoritative list of flaws that federal civilian agencies must remediate under binding operational directive. The KEV listing is also a strong signal for private-sector IT teams that active exploitation has been observed.

What to do now: check the CISA KEV Catalog for the two entries dated October 2, identify any affected systems in the environment, and apply vendor patches or mitigations within the timelines CISA specifies for each CVE.

Dell Container Storage Module Critical Flaws

Dell patched two maximum-severity vulnerabilities in its Container Storage Modules (CSM), the software that connects Dell enterprise storage arrays to Kubernetes environments. CSM supports PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT platforms and extends the standard Container Storage Interface (CSI) drivers for Kubernetes.

Both flaws live in the Dell CSM Authorization security module and stem from missing authentication for critical functions. The first, CVE-2026-63688, lets unauthenticated remote attackers access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure. The second, CVE-2026-63692, in the authorization proxy and tenant service, also grants admin privileges by bypassing authentication controls.

Dell also patched four additional critical issues the same day: CVE-2026-67269 (root on cluster nodes), CVE-2026-54472 (administrative access to the CSM Authorization proxy), CVE-2026-61421 (forged authentication tokens for administrative privileges), and CVE-2026-67273 (Kubernetes access-control bypass for cluster-wide read access to Kubernetes Secrets). Dell recommends updating container storage modules to version 1.18.0 or later.

What to do now: upgrade Dell CSM to 1.18.0 or later on every Kubernetes cluster that talks to Dell enterprise storage, and treat any unpatched cluster as high-risk until the upgrade completes.

Frontline Education Breach Exposes School District Employee Data

Frontline Education, an edtech company that provides administration and workforce management software for school districts, is notifying districts of a data breach after attackers exploited a vulnerability in a third-party software product to gain unauthorized access to its systems and steal employee information, including Social Security numbers.

On August 14, 2026, Frontline’s security team identified the vulnerability in a third-party application that allowed unauthorized access to a portion of the environment. The company investigated with an independent cybersecurity firm, remediated the vulnerability, engaged law enforcement, and took steps to further reinforce the security of its systems. Frontline has not disclosed which third-party application was involved or when the unauthorized access first occurred. In the notification reviewed by reporting outlets, all employees at the affected district were impacted, with exposed information including Social Security numbers, email addresses, and physical addresses. School IT administrators on the K12SysAdmin subreddit independently confirmed the breach notifications were legitimate.

What to do now: any school district that uses Frontline Education should check for an official breach notification, prepare credit-monitoring or identity-protection resources for affected staff, and audit which third-party applications sit in the path between Frontline and the district network. Districts that have not yet been contacted should still review their data-handling posture with Frontline and document the response.

Warlock Ransomware Targets Water, Telecom, Government, and Universities

The China-linked ransomware group Warlock targeted a water utility, a telecommunications provider, a regional government body, and a university by exploiting Microsoft SharePoint vulnerabilities to gain initial access. Over the past two months, the threat actor has focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America.

The gang emerged in June 2025 and gained notoriety a month later after exploiting a chain of zero-day vulnerabilities in on-premises SharePoint known as ToolShell (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). By August, Microsoft observed state-backed groups Linen Typhoon and Violet Typhoon using ToolShell exploits, along with a ransomware actor tracked as Storm-2603. In one intrusion that started on July 22, the threat actor deployed an EDR-killing tool that disabled protection software on at least 40 hosts within about two hours, then launched Warlock ransomware on at least 33 hosts. Researchers identified the same actor as Longlegs. In some attacks, the AV/EDR-killing tool was deployed via the bring your own vulnerable driver (BYOVD) technique using a signed K7RKScan driver vulnerable to CVE-2025-1055. Two days after gaining initial access, the threat actor conducted reconnaissance and deleted staging artifacts. The ransomware payload was staged in the SYSVOL domain share, a known method of pushing a payload out for execution by a logon script. The campaign shows continued success exploiting SharePoint deployments that remain unpatched for either the 2025 or the newer 2026 bugs.

What to do now: confirm every on-premises SharePoint farm is patched against the ToolShell chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) and the newer 2026 SharePoint vulnerabilities CISA has flagged. Monitor SYSVOL and Group Policy preferences for unexpected script changes, and restrict who can write to those locations.

The EDR Blind Spot: Browser-Based Attacks on SaaS

New reporting on endpoint detection and response coverage highlights a growing gap: many attacks now happen inside the browser and against cloud SaaS applications, where endpoint telemetry sees little or nothing. EDR still detects host execution, malware, persistence, and process-level behavior, but in SaaS-heavy environments some attacks run through browser and identity workflows that do not create the endpoint artifacts EDR was built to inspect.

Adversary-in-the-middle phishing, malicious browser extensions, unauthorized uploads, and clipboard-based execution lures all act inside the browser or the cloud application. In 2026, a threat actor tracked as Storm-2755 targeted Canadian employees through search engine poisoning and malicious ads, redirecting victims searching for Office 365 terms to a fraudulent Microsoft 365 login page. Browser access is present across nearly every SaaS application in modern environments, with 79% of tools available only through the browser, which makes browser sessions a core location for user actions that may not produce the artifacts EDR analyzes.

What to do now: extend monitoring beyond the endpoint to cover browser sessions, OAuth grants, and SaaS audit logs. Review which third-party OAuth integrations are active in Salesforce, Microsoft 365, and Google Workspace, and revoke any that are no longer in use.

What to Do This Week

  • Patch every Citrix NetScaler ADC and Gateway instance against CVE-2026-88771 and CVE-2026-88772, and audit for compromise dating back to September 24.
  • Upgrade every self-hosted GitLab AI Gateway to 19.2.4, 19.3.2, or 19.4.1, and tighten Duo Agent Platform access.
  • Move Dell CSM installations to 1.18.0 or later on every Kubernetes cluster that talks to Dell enterprise storage.
  • Check the CISA KEV Catalog for the two October 2 entries and remediate within the listed timelines.
  • Confirm on-premises SharePoint farms are patched against the 2025 ToolShell chain and the newer 2026 SharePoint bugs, and monitor SYSVOL for unauthorized changes.
  • Verify any Frontline Education breach notification, prepare identity-protection resources for affected staff, and review third-party applications in the Frontline data path.
  • Add browser-session, OAuth-grant, and SaaS-audit monitoring to the security program so attacks that never touch the endpoint are still visible.

FAQ

What is the most urgent patch this week?

The Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, are under widespread exploitation. Organizations should patch NetScaler ADC and Gateway instances immediately and audit for indicators of compromise dating back to September 24, 2026.

Are self-hosted GitLab AI Gateway users at risk from CVE-2026-90970?

Yes. The flaw allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway. GitLab has released versions 19.2.4, 19.3.2, and 19.4.1. Customers using a GitLab-hosted AI Gateway are already protected and do not need to take action.

What was exposed in the Frontline Education breach?

Attackers exploited a vulnerability in a third-party software product used by Frontline Education and stole employee information including Social Security numbers, email addresses, and physical addresses. The breach was identified on August 14, 2026, and notifications began reaching affected school districts on October 1, 2026.


This article summarizes reporting from darkreading.com, darkreading.com.

← All Articles