September 28, 2026 is shaping up to be one of the more demanding days of the year for security operations teams. Two converging threat streams — actively exploited remote code execution zero-days in Citrix NetScaler and a sophisticated WAF bypass campaign against Oracle PeopleSoft — are demanding immediate attention from SOC analysts, infrastructure teams, and security leadership alike. The common thread running through today's alerts is adversary speed: threat actors are not waiting for organizations to catch up, and in at least one case, exploitation was confirmed before many defenders had even opened their morning briefings.

The dominant story is the pair of critical zero-days in Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772. CVE-2026-88771 is an improper input validation vulnerability that allows unauthenticated remote attackers to execute arbitrary code on affected appliances. CVE-2026-88772 is a buffer overflow condition that similarly enables full remote code execution and, by extension, complete system compromise. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation. Citrix has confirmed the exploitation activity and has released patches. Beyond these two, CISA and Citrix have disclosed a total of eight critical vulnerabilities across the NetScaler ADC and Gateway product lines in this disclosure cycle, meaning the patching surface is broader than just the two headline CVEs.

Why does this matter so acutely? NetScaler ADC and Gateway appliances sit at the perimeter of thousands of enterprise and government networks, handling authentication, load balancing, and remote access. A successful RCE against one of these appliances does not merely compromise a single server — it hands an attacker a privileged vantage point from which to intercept credentials, pivot into internal segments, and potentially manipulate traffic for thousands of users. Historical exploitation of NetScaler vulnerabilities has been linked to ransomware deployment, data exfiltration, and persistent backdoor installation, so the stakes here are exceptionally high.

Shifting to the second major threat: the ShinyHunters threat group is actively exploiting CVE-2026-35273 in Oracle PeopleSoft. What makes this campaign particularly notable is the technique being used to bypass web application firewalls — URL-encoding manipulation that causes WAF rules to fail to match malicious payloads. This is a well-understood class of evasion, but it serves as a sharp reminder that WAF coverage alone is not a sufficient control. Organizations relying on WAF rules as a primary defense for PeopleSoft internet-facing instances are at immediate risk. ShinyHunters has a documented history of large-scale data theft and extortion, making the downstream consequences of a successful compromise severe.

Defensive Priorities

- Patch Citrix NetScaler ADC and Gateway immediately. Apply all available vendor patches for CVE-2026-88771, CVE-2026-88772, and the full set of eight disclosed critical vulnerabilities. Treat this as an emergency change, not a scheduled maintenance window.

- If patching cannot be completed immediately, isolate NetScaler management interfaces from internet-facing exposure and implement strict network segmentation to limit lateral movement potential from the appliance tier.

- Hunt for indicators of compromise on all NetScaler appliances before and after patching. Look for unexpected processes, new administrative accounts, unusual outbound connections, and modifications to appliance configuration files. Assume that unpatched appliances in your environment may already be compromised.

- Enable enhanced logging on NetScaler appliances and forward logs to your SIEM in real time. Alert on anomalous authentication patterns, unexpected shell execution events, and configuration changes originating from non-administrative source IPs.

- For Oracle PeopleSoft, apply the vendor patch for CVE-2026-35273 without delay. Do not treat WAF coverage as a substitute for patching — the ShinyHunters campaign demonstrates that WAF rules can be bypassed through encoding tricks.

- Audit WAF rule sets for PeopleSoft and other internet-facing applications to ensure they normalize and decode URL-encoded input before pattern matching. Work with your WAF vendor to validate that evasion via URL encoding is accounted for in your current rule configuration.

- Review PeopleSoft access logs for anomalous request patterns, particularly requests containing unusual encoding sequences or targeting administrative endpoints. Correlate with authentication logs for signs of unauthorized access.

- Verify that PeopleSoft instances are not directly internet-exposed where avoidable, and enforce multi-factor authentication on all administrative and privileged access paths.

- Cross-reference your asset inventory against the CISA KEV entries for CVE-2026-88771 and CVE-2026-88772. Federal agencies are under binding operational directive timelines; all organizations should treat KEV entries as high-urgency regardless of regulatory obligation.

Today's threat landscape underscores a recurring reality: perimeter appliances and enterprise application platforms are high-value targets precisely because they are trusted, widely deployed, and often slower to patch than endpoint systems. The combination of zero-day exploitation and WAF evasion in a single day's briefing is a signal that adversaries are investing in techniques that defeat common compensating controls. Defense-in-depth, rapid patching, and active threat hunting remain the most reliable responses.

This briefing is informational and intended to support situational awareness — always consult official Citrix, Oracle, and CISA vendor advisories for authoritative guidance and the latest patch information.