Critical Security Alerts: Kiteworks, Citrix NetScaler and Oracle PeopleSoft Vulnerabilities
- Critical software vulnerabilities and active exploitation campaigns affecting platforms such as Kiteworks, Citrix NetScaler, and Oracle PeopleSoft have forced organizations worldwide to urgently disconnect systems and apply patches.
- Kiteworks urged its enterprise customers to shut down their systems for a nine-hour window on Saturday, September 26, 2026.
- System administrators across multiple organizations were advised by IT providers to immediately shut down Citrix NetScaler instances following reports of active attacks.
Critical software vulnerabilities and active exploitation campaigns affecting platforms such as Kiteworks, Citrix NetScaler, and Oracle PeopleSoft have forced organizations worldwide to urgently disconnect systems and apply patches. The multi-pronged cybersecurity crisis involves targeted attacks on high-profile entities, including the Federal Bureau of Investigation, through a combination of zero-day exploits and previously patched flaws.
Kiteworks File-Sharing Platform Targeted
Kiteworks urged its enterprise customers to shut down their systems for a nine-hour window on Saturday, September 26, 2026. According to reporting from The Hacker News, federal intelligence authorities provided credible threat intelligence indicating that a threat actor might target specific Kiteworks infrastructure. Kiteworks stated in a notification that it had found no evidence of a compromise while advising clients to upgrade to version 9.5.1, which addresses all known vulnerabilities. Administrator.de noted that the secure file-sharing platform is deployed across several state banks, insurance providers, a media conglomerate, consulting firms, and a major automotive supplier.
https://x.com/IntCyberDigest/status/2103864155493056635
Citrix NetScaler Devices Facing Critical Exploits
System administrators across multiple organizations were advised by IT providers to immediately shut down Citrix NetScaler instances following reports of active attacks. The German Federal Office for Information Security, the BSI, previously issued an advisory on March 23, 2026, regarding severe vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The advisory highlighted a critical out-of-bounds read vulnerability tracked as CVE-2026-3055 with a CVSS score of 9.3, which allows unauthenticated attackers to read sensitive memory data. A second high-severity race condition flaw, CVE-2026-4368, carries a CVSS score of 7.7 and permits session confusion among users. Recent social media alerts also pointed to newly discovered CVEs enabling simple remote code execution on the platform.

Oracle PeopleSoft Flaw Exploited by ShinyHunters
The cybercriminal group ShinyHunters, tracked as UNC6240, has launched mass exploitation campaigns using a critical Oracle PeopleSoft security flaw. Mandiant and the Google Threat Intelligence Group reported that the attacks target CVE-2026-35273, a vulnerability carrying a CVSS score of 9.8 that was initially patched in June 2026. The flaw allows attackers to easily bypass web application firewalls. Google documented that the campaign has expanded from universities into the healthcare, public, technology, and transportation sectors, with servers frequently receiving a backdoor named SIDEEYE. The breach of FBI servers, confirmed on Friday, September 25, 2026, reportedly exploited this PeopleSoft vulnerability, according to details published by The Register. The incident exposed personal information belonging to FBI employees and applicants, confirming that the agency operated unpatched PeopleSoft servers months after the patch release. Concurrently, security tracking revealed that ShinyHunters managed to infiltrate the infrastructure of rival ransomware group Cl0p, defacing its darknet site.
https://x.com/DarkWebInformer/status/2103631790841929823
