← All briefings

Citrix NetScaler ADC and NetScaler Gateway · MLflow · Splunk Enterprise

Date: 2026-08-20 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

A critical authentication bypass in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-19490, CVSS 9.3) was disclosed on 2026-08-19 and warrants immediate patching given the perimeter-facing deployment of these devices. CISA added CVE-2026-64849 (MLflow SSRF) to the KEV catalog with a 2026-09-02 deadline, formalizing the active exploitation already reported yesterday. Splunk released a large batch of high-severity patches covering RCE, privilege escalation, and unauthenticated access across Enterprise and add-on products. Password spraying attacks have surged 155× in H1 2026, exploiting MFA gaps at scale.


Critical Vulnerabilities

CVE-2026-19490 — Citrix NetScaler ADC and NetScaler Gateway (Authentication Bypass)

  • Severity: CVSS v4.0 9.3 (Critical)
  • EPSS: Not yet scored
  • Technical detail: An unauthenticated remote attacker can bypass authentication on NetScaler ADC and NetScaler Gateway without user interaction or elevated privileges. These devices are typically deployed at the network perimeter as SSL-VPN and load-balancing gateways, making unauthenticated bypass directly exploitable from the internet. Successful exploitation could grant full access to the management plane or proxied internal resources. CERT-EU issued advisory 2026-010 on 2026-08-19.
  • Exploitation status: No confirmed in-the-wild exploitation reported at time of writing; CERT-EU recommends immediate patching.
  • Remediation: Apply Citrix security updates published 2026-08-19. Restrict management interface access to trusted networks. Monitor for anomalous authentication events and unexpected session creation.

CVE-2026-64849 — MLflow (Server-Side Request Forgery) — STATUS CHANGE

  • Severity: Not yet assigned (CWE-918)
  • EPSS: Not yet scored; CISA KEV confirmed active exploitation
  • Update: CISA formally added this to the KEV catalog on 2026-08-19 (deadline 2026-09-02), confirming active exploitation previously reported as observed scanning activity. Attackers are targeting cloud metadata services (169.254.169.254) to harvest IAM credentials and service account tokens from ML infrastructure.
  • Remediation: Apply MLflow patch immediately. Audit cloud IAM roles attached to MLflow instances for unauthorized access or credential use. Enforce IMDSv2 on AWS instances to limit SSRF impact.

CVE-2026-76316 — Splunk Enterprise (Unauthenticated RCE via Management Port)

  • Severity: CVSS 8.8
  • EPSS: Not yet scored
  • Technical detail: An unauthenticated attacker who can reach the Splunk management port can store a crafted SPL pipeline that executes on the Splunk server. This is the highest-severity item in a large batch of Splunk vulnerabilities published 2026-08-19. Multiple additional CVEs in the same release allow low-privileged authenticated users to achieve RCE via Federated Search (CVE-2026-76319), scripted lookups (CVE-2026-76352), malicious file uploads (CVE-2026-76313), and crafted SPL commands (CVE-2026-76314). Affected versions: Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
  • Exploitation status: No confirmed in-the-wild exploitation; unauthenticated management-port RCE warrants urgent treatment.
  • Remediation: Upgrade Splunk Enterprise to 10.4.2 / 10.2.6 / 10.0.9 / 9.4.14 as appropriate. Restrict the Splunk management port (default 8089) to trusted administrative networks. Also update Splunk MCP Server app to ≥1.2.1 and Splunk AI Toolkit to ≥6.0.0.

CVE-2026-16919 / CVE-2026-16913 / CVE-2026-16894 — IBM AIX and PowerVM VIOS (Multiple Remote RCE)

  • Severity: CVSS 9.8 (multiple CVEs)
  • EPSS: Not yet scored
  • Technical detail: IBM published a cluster of critical RCE vulnerabilities in AIX 7.2/7.3 and PowerVM VIOS 4.1 on 2026-08-19, including stack buffer overflows, integer overflows, and improper pointer validation in network-accessible components. At least five CVEs carry CVSS 9.8; a further CVE (CVE-2026-16835) affecting IBM Power Systems Firmware scores 9.6. These affect enterprise UNIX and virtualization infrastructure common in financial services, manufacturing, and government sectors.
  • Exploitation status: No confirmed exploitation; CVSS 9.8 network-exploitable RCE in production UNIX/hypervisor infrastructure warrants urgent treatment.
  • Remediation: Apply IBM AIX and PowerVM VIOS security fixes published 2026-08-19. Apply IBM Power Systems Firmware updates. Restrict network access to affected services pending patching.

CVE-2026-55089 — Etherpad (OAuth Authorization Bypass / Near-Unauthenticated RCE)

  • Severity: CVSS 9.9
  • EPSS: 0 (newly published)
  • Technical detail: In Etherpad versions 2.1.0 through 3.1.0, the API authorization logic for /api/2/* in the OAuth authorization_code path uses an insufficiently validated client check, allowing an attacker to effectively bypass authorization and interact with the API as a privileged client. CVSS 9.9 reflects near-complete impact. Etherpad is widely used for collaborative document editing in European public sector and academic environments.
  • Exploitation status: No confirmed exploitation; severity and broad deployment warrant prompt action.
  • Remediation: Upgrade to Etherpad ≥3.1.0. Restrict API access to trusted networks where upgrade is not immediately possible.

ONGOING:

  • CVE-2026-33824 (Microsoft IKE): CISA KEV deadline 2026-08-21 — patch immediately if not done.
  • CVE-2026-65400 (Apple macOS Screen Sharing): CISA KEV deadline 2026-08-21 — deploy macOS 26.6.2 via MDM.
  • CVE-2026-59310 (VMware vCenter): CISA KEV deadline 2026-08-21 — patch immediately.
  • CVE-2026-55040 (SharePoint): CISA KEV deadline 2026-08-21 — apply July 2026 Patch Tuesday.
  • CVE-2026-18963 (Keycloak): CVSS 9.1 auth bypass — upgrade to patched build; audit reset-credentials activity.
  • CVE-2026-21582 (Atlassian Crowd): CVSS 8.8 broken auth — apply patch; review session logs.
  • CVE-2026-24301 (Microsoft Copilot Web): CVSS 8.8 command injection — apply patch; review connector permissions.
  • CVE-2025-62593 (Anyscale Ray): KEV deadline was 2026-08-20 — verify patch applied immediately.
  • CVE-2026-68820 (Windows AFD/Lazarus): KEV deadline 2026-08-25 — apply August Patch Tuesday.
  • CVE-2026-69414 (Microsoft Defender ShieldBreak): Unpatched zero-day — monitor MSRC, enforce least privilege.
  • CVE-2026-19478 (GitLab), CVE-2026-15748 (Forminator), CVE-2026-47686/47698 (vm2), CVE-2026-58231 (SAP), CVE-2026-63077 (TeamCity), CVE-2026-0257 (PAN-OS), CVE-2026-16232 (Check Point), CVE-2026-48907 (Joomla JCE), CVE-2026-18438 (Templately), CVE-2026-15826 (User Profile Builder), CVE-2026-8037 (Kemp LoadMaster): patch actions unchanged from prior reporting.

European Advisories

CERT-EU 2026-010 — Citrix NetScaler ADC / NetScaler Gateway (Critical): Published 2026-08-19. Covered in full under Critical Vulnerabilities (CVE-2026-19490).

BSI — New and Updated Advisories (2026-08-19):

WID-SEC-2026-1686 (Samba — kritisch, UPDATE): Updated advisory covering multiple Samba vulnerabilities enabling arbitrary code execution, DoS, file manipulation, and security bypass. Apply current Samba security updates; relevant for Linux/Unix file servers and Active Directory domain controllers using Samba.

WID-SEC-2026-2926 (Joomla — hoch, NEU): Multiple vulnerabilities including RCE, information disclosure, file manipulation, XSS, and security bypass. Note: CVE-2026-48907 (Joomla JCE with public Metasploit module) remains ongoing — treat unpatched instances as compromised.

WID-SEC-2026-2923 (Atlassian Bamboo, Bitbucket, Confluence, Crucible, Fisheye, Jira — hoch, NEU): Multiple vulnerabilities across the full Atlassian suite including RCE, DoS, SQLi, XSS, and security bypass. Apply current Atlassian security updates across all affected products.

WID-SEC-2026-2918 (OpenBao — hoch, NEU): A remote unauthenticated attacker can bypass security controls in OpenBao (the open-source HashiCorp Vault fork). Relevant for organizations using OpenBao as a secrets management platform. Apply the latest OpenBao update.

WID-SEC-2026-2916 (Zabbix — hoch, NEU): Multiple vulnerabilities including potential code execution, information disclosure, XSS, DoS, and security bypass in the widely deployed Zabbix monitoring platform. Apply Zabbix security updates; compromise of a monitoring platform has detection-evasion implications.

WID-SEC-2026-2915 (Keycloak — hoch, NEU): Covered in Critical Vulnerabilities (CVE-2026-18963).

BSI also published updates for IBM App Connect Enterprise (WID-SEC-2026-2919), ISC BIND, Oracle MySQL, Linux Kernel (multiple advisories), Erlang/OTP, Golang Go, and Microsoft Developer Tools — apply vendor patches per standard cycle.


Active Threats and Campaigns

NEW — Operation CameraSwarm (Dahua IP Cameras): Hunt.io researchers documented a 35-day campaign (June 17–July 22, 2026) that compromised over 14,500 Dahua IP cameras using credential attacks, two authentication-bypass flaws, and a P2P relay technique. Affected devices are concentrated in Ukraine and Russia but the campaign infrastructure is global. Organizations using Dahua cameras should audit for unauthorized access, rotate credentials, and apply available firmware patches. (The Hacker News)

NEW — SilkParasite Espionage Campaign: A previously undocumented espionage operation targeting Central Asian government bodies, deploying seven RAT families — five novel (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT). First observed late 2025; attribution is not yet established. While geographically focused on Central Asia, the novel tooling warrants IOC collection for European government threat hunting. (The Hacker News)

NEW — MacSync Stealer Infrastructure (macOS): Microsoft Defender Experts linked 30+ rotating domains to MacSync Stealer, a macOS information stealer, by correlating endpoint and network behaviors across changing infrastructure. Relevant for organizations with macOS endpoints, particularly given the concurrent active exploitation of CVE-2026-65400. (The Hacker News)

NEW — StopAndProtect WordPress Malware Network: A global cybercrime operation is abusing nearly 2,000 compromised WordPress sites as malware distribution and data exfiltration infrastructure, deploying a multi-tool criminal toolkit. Organizations hosting or relying on WordPress sites should audit for compromise indicators. (The Hacker News)

NEW — Password Spraying Surge (155× increase): Huntress observed a 155× increase in password spraying in H1 2026, including a single campaign generating 81 million login attempts in two weeks. Attacks exploit legacy authentication protocols and MFA policy gaps. Enforce MFA universally and disable legacy authentication endpoints. (Bleeping Computer)

ONGOING — TWINLOOT (SharePoint/Teams C2): No new developments; audit M365 API access logs for anomalous automated activity. ONGOING — Clop / PTC Windchill web shell: No new developments; treat unpatched internet-exposed instances as compromised. ONGOING — MLflow SSRF active exploitation: Now CISA KEV — see Critical Vulnerabilities.


Security News and Context

  • Cloudflare Workers Spectre attack: Researchers demonstrated a remote Spectre side-channel attack leaking JWTs from co-located Cloudflare Workers at 12 bits/second — 360× faster than prior work. Relevant for multi-tenant serverless deployments. (The Hacker News)
  • CareCloud healthcare breach: U.S. healthtech firm CareCloud confirmed a data breach affecting 3.7 million patients. (Bleeping Computer)
  • Medusa ransomware: CISA/FBI report Medusa ransomware has breached over 500 critical infrastructure organizations since 2021. (Bleeping Computer)
  • US charges Iranian hackers: 17 members of the Mabna Institute charged over $3.4 billion in intellectual property theft from US organizations. (Bleeping Computer)

  1. CVE-2026-19490 (Citrix NetScaler ADC/Gateway): Apply Citrix patches published 2026-08-19 immediately; restrict management interface to trusted networks.
  2. CVE-2026-64849 (MLflow SSRF): Apply patch; audit cloud IAM for unauthorized credential use — CISA KEV deadline 2026-09-02.
  3. CVE-2026-33824 / CVE-2026-65400 / CVE-2026-59310 / CVE-2026-55040: CISA KEV deadline 2026-08-21 tomorrow — verify patches applied for IKE, macOS Screen Sharing, vCenter, and SharePoint.
  4. Splunk Enterprise (CVE-2026-76316 et al.): Upgrade to 10.4.2 / 10.2.6 / 10.0.9 / 9.4.14; restrict management port 8089 to trusted networks.
  5. IBM AIX / PowerVM VIOS: Apply IBM security fixes for CVSS 9.8 RCE cluster; restrict network access to affected services.
  6. Etherpad (CVE-2026-55089): Upgrade to ≥3.1.0; restrict API access to trusted networks.
  7. Samba (WID-SEC-2026-1686): Apply current Samba updates — critical severity, updated advisory.
  8. Atlassian suite (WID-SEC-2026-2923) / Zabbix / OpenBao: Apply vendor patches; Zabbix compromise has detection-evasion implications — prioritize.
  9. Password spraying: Disable legacy authentication protocols; enforce MFA on all login flows including service accounts; review Entra/AD sign-in logs for spray patterns.
  10. Continue remediation of previously reported items: CVE-2025-62593 (Ray — deadline today), CVE-2026-68820 (Windows/Lazarus — deadline 2026-08-25), CVE-2026-18963 (Keycloak), CVE-2026-21582 (Atlassian Crowd), CVE-2026-69414 (Defender ShieldBreak — no patch), CVE-2026-19478 (GitLab), CVE-2026-58231 (SAP), CVE-2026-63077 (TeamCity), CVE-2026-0257 (PAN-OS), CVE-2026-16232 (Check Point).