Menu Close

Today’s Virus Report: September 28, 2026

Virus

Federal agencies and enterprise security teams face a critical deadline today. Network administrators must patch multiple severe vulnerabilities before the day ends. The virus threat environment escalated over the weekend when vendors rushed emergency fixes for hardware gateways and collaboration servers. Attackers use these software flaws to break into corporate networks and deploy malware without needing employee passwords. Reading direct alerts from the Cybersecurity and Infrastructure Security Agency (CISA) provides IT departments with the exact technical steps needed to secure vulnerable networks today.

Emergency Action Required for Citrix NetScaler

Over the weekend, Citrix rushed out patches for two critical zero-day vulnerabilities affecting NetScaler deployments. Federal authorities ordered agencies to patch these systems by September 30. The first flaw, tracked as CVE-2026-88771, allows an unauthenticated attacker to execute malicious commands remotely. The second vulnerability, CVE-2026-88772, creates a memory overflow that crashes the appliance or allows remote code execution.

Attackers exploit these flaws against appliances running default configurations, particularly virtual private network (VPN) servers. Attackers actively target these systems, forcing administrators to apply the security updates immediately. Monitoring these hardware exploitation methods through our active virus campaigns database helps defenders spot early warning signs before a hacker takes full control of the network perimeter.

Microsoft SharePoint Under Active Exploitation

The threat environment remains highly dangerous for organizations running on-premises Microsoft software. Security officials recently added a severe bug affecting Microsoft SharePoint Server to the active threat catalog. Tracked as CVE-2026-65660, this code injection vulnerability carries a high severity score of 8.8.

Hackers use this flaw to run malicious code directly on the server. Once they gain access, attackers can steal sensitive internal documents, alter records, and move laterally into other parts of the corporate network. Applying vulnerability management standards published by the National Institute of Standards and Technology helps administrators isolate these compromised servers from the rest of the company infrastructure.

Sharepoint Virus

F5 BIG-IP and Precautionary Software Shutdowns

Hardware devices that manage network traffic continue to attract heavy cybercriminal attention. Early this morning, researchers flagged an active exploitation alert for F5 BIG-IP Access Policy Manager. Tracked as CVE-2026-94127, this remote code execution vulnerability targets the OAuth authorization server.

The threat level escalated so fast that secure file transfer platform Kiteworks issued an unprecedented advisory over the weekend. The company urged customers to shut down their self-managed systems for nine hours to prevent a potential zero-day attack across the healthcare and government sectors.

September 28 Active Threat Data

Security teams must prioritize the immediate dangers circulating today. The table below outlines the primary targets and methods of these active threats.

Threat Target / FlawPrimary Attack MethodMain Operational Goal
Citrix NetScalerCVE-2026-88771 command executionBypassing perimeter security on VPN servers
Microsoft SharePointCVE-2026-65660 code injectionStealing internal documents and data
F5 BIG-IP APMCVE-2026-94127 remote code executionBreaching authorization gateways
Kiteworks SystemsUnspecified zero-day attacksTargeting secure file transfers

Steps to Secure Your Network Today

Administrators must enforce strict security protocols to survive this environment. Never assume your servers are safe using default firewall settings. The ongoing attacks on F5 and Citrix gateways prove that modern threats bypass standard defenses easily.

Update all external software immediately. Prioritize patches for internet-facing systems like remote access gateways and file transfer platforms. Isolate any system exhibiting signs of unusual administrative traffic. Reviewing technical mitigation strategies through the SANS Institute helps you apply the correct hardening measures for your data centers.