Secret CISO 9/28: SharePoint KEV RCE, Citrix NetScaler RCE, Berlin Data Theft, Cloudflare Container Leak

Today’s pattern is ugly but useful: attackers are living in the gap between “we have a patch” and “we have proof nobody can hit it.” KEV deadlines, edge appliances, and tenant-isolation bugs are doing the same job: turning small mistakes into org-wide access.

Share
Citrix NetScaler RCE bulletin (CVE-2026-88771)

Attackers are having a productive weekend because defenders keep treating “patched” as a synonym for “safe.” Today’s stories are all about the lag between an advisory, a deadline, and the first real compromise.

Today's Top 5

  1. 9/28 SharePoint KEV deadline: Microsoft’s SharePoint RCE CVE-2026-65660 is now confirmed exploited in the wild, and the clock hits zero today for federal remediation. Who’s still running August builds?
  2. Citrix NetScaler unauth RCE: Citrix dropped a bulletin for CVE-2026-88771 with a 9.5 score. The timing, and the shutdown rumors from admins, should make every edge owner uneasy.
  3. Berlin confirms data theft: The city administration says extortionists stole data after a Rhysida hit. Confirmation changes the operational posture, and the next question is what was in the loot.
  4. Cloudflare container residue: Cloudflare fixed a cross-tenant Containers flaw that could have crossed isolation boundaries and exposed metadata and app data. Multi-tenant bugs are back in fashion, sadly.
  5. MikroTik takeover chain: RouterOS exploitation is active, and CVE-2026-67279 is now in KEV alongside SharePoint. If SSH is internet-exposed, you are playing on hard mode.

Why today matters: Three different fronts, SharePoint servers, NetScaler appliances, and MikroTik routers, all show the same attacker math: hit the edge, move fast, and monetize before patch cycles catch up. The scary part is the “in-between state” where teams have mitigations, but not verification. If you run any customer-facing management plane, you should assume scanners are already looking for your exact build string.

Okay, let’s turn the noise into a to-do list.

Data Breaches

Berlin city administration data theft confirmation
  1. Berlin confirms data theft after Rhysida ransomware extortion: Berlin’s city administration confirmed that data was stolen and criminals are attempting to extort the city after a Rhysida listing. This moves the incident from rumor to response mode, and drives immediate containment plus exposure mapping. Source: BleepingComputer
  2. Astrana Health reports cyber incident after phone spoofing social engineering: Astrana’s SEC disclosure describes attackers impersonating personnel and spoofing the company’s main phone number to gain access, with private or confidential info potentially accessed. This is the modern helpdesk breach with a caller ID costume. Source: The Record
  3. Astrana Health breach detail: spoofed corporate phone number used to seek access: Additional reporting highlights the same technique, spoofing the organization’s own phone number as part of the pretext. The key takeaway is how quickly identity checks collapse when the “inside number” is forged. Source: blacktree.nl

Security Research

Cloudflare Containers cross-tenant data exposure flaw
  1. Microsoft SharePoint RCE is now exploited in the wild: CVE-2026-65660 moved from “patch available” to “observed attacks,” and CISA KEV pressure follows. The most important detail is operational: the exploit window opened weeks after Patch Tuesday, not hours. Source: SecurityWeek
  2. Citrix NetScaler zero-days rumored exploited before patches: Reports say two unpatched NetScaler zero-days are being exploited, with agencies and providers advising shutdowns while the community waits for fixes. Even if you cannot validate the rumor, you can validate your exposure. Source: BleepingComputer
  3. Cloudflare fixes Containers cross-tenant isolation flaw: The bug could have allowed residual data recovery across customers on the same host, including directory listings, database pages, and secrets in .env files. Cloud providers are not magic, they are software. Source: BleepingComputer
  4. SharePoint and MikroTik vulnerabilities added to KEV due to active exploitation: CISA’s KEV additions underscore how quickly edge and server bugs become mass exploitation candidates once details land. Treat KEV as an attack roadmap, not a compliance list. Source: The Hacker News
  5. WordPress core RCE exploited within hours of disclosure: Patchstack saw exploitation attempts targeting CVE-2026-87902 shortly after public disclosure and the 7.1.2 fix. Public CMS bugs still deliver an instant botnet-shaped response. Source: SecurityWeek

Top CVEs

Microsoft SharePoint CVE-2026-65660 KEV deadline
  1. CVE-2026-65660: Microsoft SharePoint code injection RCE now confirmed exploited in the wild. If you run SharePoint on-prem, treat this like an incident until proven otherwise, patching is table stakes, hunting is the meal. Source
  2. CVE-2026-88771: Citrix NetScaler ADC and Gateway unauthenticated RCE due to improper input validation, CVSS 9.5. This is edge gear, so assume internet scanning and prioritize emergency change windows. Source
  3. CVE-2026-67279: MikroTik RouterOS flaw listed as actively exploited and added to KEV, commonly discussed as part of takeover chains. If SSH management is exposed, you are a target in practice, not theory. Source
  4. CVE-2026-87902: WordPress Core critical issue patched in 7.1.2, with exploitation attempts observed soon after disclosure. Assume opportunistic mass scanning and verify integrity of theme and plugin files after patching. Source

Podcasts & Talks

SANS Stormcast on ClickFix and malicious Terraform
  1. SANS Stormcast, Thursday September 24, 2026: Macfinger ClickFix; malicious Terraform; MikroTik analysis: A fast, CISO-friendly run through what’s actually getting exploited and how supply chain tricks are targeting specific environments. Good listening for your incident commander and your cloud engineering lead. Listen: SANS ISC

Final Words

The connective tissue today is verification, not vulnerability. Every org has a patch process. Fewer have a proof process that shows, in logs and in controls, that the exploit path is closed, and that nobody already walked through it. The uncomfortable implication is that “deadline-driven security” quietly trains teams to optimize for patch dates instead of adversary timelines.

This week, do three things:

  • Patch and then hunt for post-exploitation on Microsoft SharePoint servers for CVE-2026-65660, including webshell indicators and suspicious child processes under IIS worker contexts.
  • Inventory every Citrix NetScaler ADC and Gateway instance, confirm exposure paths, and prepare an emergency maintenance plan tied to CVE-2026-88771 and related NetScaler bulletin items.
  • Find and remove any internet-exposed MikroTik RouterOS SSH management, then validate RouterOS versions and patch for CVE-2026-67279 class takeover chains.

Your turn: If an auditor asked you tomorrow to prove, with evidence, that your SharePoint farm was not exploited before you patched, what would you show? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.

Know someone who still treats edge appliances as “set and forget”? Forward them this issue and point them at the NetScaler and MikroTik sections. It costs 30 seconds and the alternative costs a weekend. For everyone else, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!