Opens in a new tab

Security Roundup, October 6: NetScaler Denial of Service and Dell System Update Flaw

  • Home
  • Blog
  • Security Roundup, October 6: NetScaler Denial of Service and Dell System Update Flaw
NetScaler server under cyber attack in security roundup alert

Two urgent flaws top today’s security picture. A memory overflow bug in Citrix NetScaler is being exploited to crash appliances, and a path traversal flaw in Dell System Update lets remote attackers run code as root on PowerEdge servers. Federal agencies have been ordered to patch the NetScaler issue by Wednesday. Healthcare and education organizations are also disclosing ransomware incidents that exposed patient and student data.

What is happening with the Citrix NetScaler flaw CVE-2026-88779

CISA has added a newly exploited Citrix NetScaler vulnerability, CVE-2026-88779, to its Known Exploited Vulnerabilities catalog. The bug is a memory overflow that can crash vulnerable NetScaler ADC and NetScaler Gateway appliances. Citrix confirmed it has observed targeted attacks on unmitigated deployments that lead to Denial of Service, and that repeated exploitation can keep the service unavailable. Vendor analysis indicates the issue affects service availability, with no identified impact on the integrity of customer data. CISA has ordered all U.S. federal agencies to patch by Wednesday and conduct forensic triage.

The vulnerability carries a severity score of 8.7 out of 10. Exploitation only affects on-premises NetScaler deployments that have been configured to use SAML authentication, either as a service provider or identity provider. Affected supported versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, NetScaler ADC FIPS before 14.1-73.41 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.282. Citrix released mitigations that can be applied before a full upgrade is installed.

Independent security firms Bishop Fox and watchTowr were credited with identifying the flaw, and watchTowr has reproduced it. Organizations that recently upgraded to patch eight other vulnerabilities, including two actively exploited zero-days (CVE-2026-88771 and CVE-2026-88772), began reporting crashes and reboots afterward. Attackers appear to be trying to use the new bug to download and run a script that installs webshells. Researchers have observed probing and exploitation activity from multiple IP addresses. The new issue is not technically linked to last week’s vulnerabilities, but the denial of service pattern may be used to crash machines and speed up exploitation of the earlier zero-days.

Patch CVE-2026-88779 immediately on every affected NetScaler appliance, apply the available mitigations if patching must wait, audit SAML-enabled appliances first because they are the active target, review appliance logs for crash and reboot events, and hunt for webshell artifacts on any device that has shown suspicious behavior.

How does the Dell System Update flaw CVE-2026-86360 enable root access

Dell warned customers to patch a critical vulnerability in the Dell System Update (DSU) command-line interface deployment tool. Tracked as CVE-2026-86360, the flaw is a path traversal weakness that allows an unauthenticated remote attacker to execute arbitrary code with root privileges on unpatched devices. DSU is used by enterprise IT administrators to deploy BIOS, firmware, and software updates onto Linux and Windows systems running on PowerEdge server infrastructure. Successful exploitation may allow complete compromise of the vulnerable application and the underlying operating system.

On the same Thursday, Dell also patched four high-severity DSU flaws: two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362). Dell has not flagged any of these flaws as actively exploited, but state-backed hacking groups have abused other Dell vulnerabilities in attacks in recent years. Dell recommends updating Dell System Update to version 2.3.0.0 or later.

The same day, Dell urged IT administrators to patch two maximum-severity Container Storage Modules vulnerabilities (CVE-2026-63688 and CVE-2026-63692). The FBI and CISA have asked software companies since May 2024 to remove path traversal weaknesses before shipping, calling such issues unforgivable since at least 2007.

Update DSU to 2.3.0.0 or later across every managed PowerEdge server, patch the four high-severity DSU flaws in the same change window, review Container Storage Modules exposure, and confirm that management interfaces for DSU are not exposed to the public internet.

What ransomware incidents hit healthcare and education this week

The University of Illinois Chicago (UIC) discovered a ransomware attack that limited access to some systems at its College of Medicine. Hackers were able to steal some information held on the college’s servers, and an investigation is underway to determine whether any personal, research, or academic information was compromised. Some College of Medicine systems were temporarily unavailable, but all affected systems have since been restored. The university’s main network was not affected, and there was no impact on patient care delivery at UI Health. The incident was reported to law enforcement. UIC plans to notify anyone whose information was stolen. UIC is the largest university in the city it serves and enrolls more than 35,000 students across 16 colleges; the College of Medicine has about 1,300 students.

A ransomware group called Booba claimed the attack last week and said it stole 344 gigabytes of data. The group emerged at the end of July and has claimed multiple attacks since. Researchers have noted that Booba appears to be a rebrand of the Frag ransomware operation based on the leak site’s style and negotiation flow. Encrypted files are renamed with the .booba extension, and there are variants for Linux as well as Windows. The group has targeted companies and small county governments, including Merrimack County, New Hampshire.

Separately, two healthcare organizations are notifying more than 250,000 people that their information was stolen in separate July data breaches. Jersey City, New Jersey-based Clover Health Investments was hacked in early July after attackers used social engineering to compromise three non-managerial health plan employee accounts. The incident resulted in the theft of personally identifiable information and protected health information. Potentially affected information included names, dates of birth, insurance identifiers, and account identification numbers. In mid-September, Clover told the Department of Health and Human Services that 138,677 people were affected.

Mansfield, Texas-based AngMar Management Services identified suspicious activity on its systems in mid-July and confirmed in early September that hackers stole patient PII and PHI. AngMar provides business operations, administration, and support network management for home health and hospice care providers. Impacted information includes names, birth dates, Social Security numbers, diagnosis details, medical history data, health insurance information, patient IDs, provider names, prescription details, and dates of service. The Interlock ransomware group added AngMar to its leak site in August, claiming to have stolen over 700 gigabytes of data. On September 16, the company notified HHS that 126,196 individuals were affected.

Review third-party and contractor access paths into medical school and college systems, harden employee help desk procedures against social engineering, audit exposure of file transfer and remote management tools, verify that offline backups are in place for clinical and research data, and confirm a clear ransomware playbook exists for incident notification and HHS reporting.

What other flaws require attention

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability tracked as CVE-2026-61500 that allows session forgery, account takeover, and remote code execution. Honeypots have observed probes targeting the flaw, with activity appearing to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States. Rejetto HFS is a free, open-source file-sharing server used for self-hosted file sharing on Windows, Linux, and macOS. The flaw affects version 3.0.0 through 3.2.0 and is fixed in version 3.2.1. Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator’s state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration feature.

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit to deploy a botnet malware called Cling. The malware is notable because it repurposes ordinary STUN behavior into a practical command-and-control channel, producing traffic that can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling, and denial-of-service commands. Exploitation attempts spiked starting around September 5, 2026, targeting CVE-2021-35394, a critical remote code execution flaw in the Realtek Jungle SDK. A subset of the activity delivered Cling. The sample embeds exploit logic for multiple command injection and RCE vulnerabilities across routers and DVRs from several vendors.

CISA has also warned of active exploitation of a critical Fortinet FortiMail flaw, CVE-2026-104286, with a CVSS score of 9.8, that allows unauthenticated attackers to write arbitrary files on the underlying system. Federal agencies have been given a tight patching deadline.

How can enterprises evaluate AI security agents

Hack The Box has introduced AI Range Enterprise Edition, making its platform for testing and measuring AI security agent effectiveness available to enterprise security teams. The offering enables organizations to evaluate whether their own AI agents can perform the cybersecurity roles assigned to them and make informed decisions about how to use agents across the workforce. Companies often assess whether people can do the job they were hired to do, but AI agents may not face the same scrutiny. A security team may add agents after they perform well in a benchmark or vendor test, without testing them against the actual work they will handle continuously. As models, software, data inputs, and threats change, AI agent performance can change too.

Hack The Box introduced AI Range in December 2025 to test AI security agents in controlled cyber environments. Since then, the platform has been pressure-tested by AI labs, government customers, and hyperscalers. AI Range Enterprise Edition builds on that foundation with a role-based appraisal process security teams can apply to their own agents. The platform offers Agentic Worker Competence, which lets organizations appraise their own AI agents against defined cybersecurity roles and build recurring, evidence-based proof that an agent can perform a specific job role to the expected standard. It also offers Agentic Operator Competence Scoring, which uses AI-augmented roles to evaluate whether cybersecurity professionals have the judgment to question the work of AI agents and intervene when needed. AI-augmented penetration tester and SOC analyst roles are available now, with additional cybersecurity roles planned in the coming months.

What to do this week

Patch NetScaler ADC and Gateway to the fixed versions listed above or apply Citrix’s pre-upgrade mitigations, and audit SAML-enabled appliances for crash and reboot events. Update Dell System Update to 2.3.0.0 or later on every managed PowerEdge server, and review DSU and Container Storage Modules exposure to the internet. Update Rejetto HFS to version 3.2.1 on Windows, Linux, and macOS hosts that expose it, and watch for probing activity from a small set of China Telecom IP addresses targeting Japan and U.S. networks. Review and patch Fortinet FortiMail against CVE-2026-104286 ahead of the federal deadline. Harden help desk procedures against social engineering at healthcare organizations, verify offline backups for medical and research systems, and rehearse the ransomware notification workflow. For any organization piloting AI security agents, test those agents against the actual work they will handle continuously, not only vendor benchmarks.

FAQ

What is CVE-2026-88779 and who is affected?

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can crash vulnerable appliances. It affects on-premises deployments configured to use SAML authentication. Affected supported versions include NetScaler ADC and Gateway 14.1 before 14.1-73.41, 13.1 before 13.1-64.28, NetScaler ADC FIPS before 14.1-73.41 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.282.

How severe is the Dell System Update flaw CVE-2026-86360?

CVE-2026-86360 is a critical path traversal flaw in Dell System Update (DSU) that lets an unauthenticated remote attacker execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends updating DSU to 2.3.0.0 or later.

Which ransomware groups are behind the latest healthcare and education attacks?

A group calling itself Booba claimed the University of Illinois Chicago College of Medicine attack and said it stole 344 gigabytes of data. The Interlock ransomware group added AngMar Management Services to its leak site in August, claiming to have stolen over 700 gigabytes of data. Clover Health Investments was compromised through social engineering of three non-managerial employee accounts, with 138,677 people affected, while AngMar reported 126,196 individuals affected.


This article summarizes reporting from helpnetsecurity.com.

← All Articles