Cyware Daily Threat Intelligence - September 27, 2026

Summary
Attackers are actively exploiting two undisclosed remote code execution zero-days in Citrix NetScaler, putting exposed ADC and Gateway appliances at risk of takeover before defenders even have a CVE to track. Cyware.com highlights how a single compromise at the edge can disrupt VPN access, application delivery, and authentication services, forcing teams to consider shutting down internet-facing appliances to contain the threat.
A critical flaw in the Linux kernel’s AF_ALG subsystem, tracked as CVE-2025-39964, enables local attackers to escalate privileges to root and potentially escape Docker containers on affected systems. The vulnerability spans kernel versions 2.6.38 to 6.12.44, and exploitation can lead to arbitrary command execution as root by manipulating kernel behavior.
A critical unauthenticated SQL injection in Netsis NetOpenX REST 2.0.6.9 can be chained into OS command execution, giving attackers a path to the ERP database host and sensitive financial data. The flaw, which scores up to 9.8 CVSS when SQL logins have sysadmin privileges, is reachable through the OAuth 2.0 token endpoint and exposes unpatched deployments to external attack.
Top Vulnerabilities Reported in Last 24 hours
Unpatched NetScaler bugs reportedly hit in wild
Reports say two undisclosed remote code execution zero-days in Citrix NetScaler are being exploited, raising the risk that attackers could take control of exposed ADC and Gateway appliances even before defenders have a CVE to track. In practical terms, a compromise at the edge can quickly turn into disrupted VPN access, application delivery, and authentication services—especially if teams are forced to shut down internet-facing appliances to contain risk. Attackers are reportedly exploiting this in the wild, but public technical details, exploitation paths, and forensic artifacts have not been disclosed. Citrix has not released CVE identifiers or specific guidance for these new issues, and the report stresses treating the claims as serious warnings rather than social-media noise. Recommended actions in the report include inventorying every NetScaler instance, preserving logs and forensic images, and monitoring Citrix’s security bulletin channel for updates.
Linux kernel bug enables root and escape
A critical Linux kernel flaw in the AF_ALG subsystem (CVE-2025-39964) can let a local attacker escalate privileges to root and potentially break out of a Docker container on affected systems. The write-up describes how exploitation can lead to arbitrary command execution as root by manipulating kernel behavior, turning a foothold on one workload into control of the host. The source describes exploitation through concurrent AF_ALG activity that results in out-of-bounds access and the ability to write to sensitive kernel-controlled locations. Researchers publishing the analysis position it as a serious privilege-escalation risk across Linux kernel versions 2.6.38 to 6.12.44. A patch is available via commit 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285, and the report also calls for monitoring for unusual activity related to AF_ALG socket usage.
ERP API flaw can run OS commands
A critical unauthenticated SQL injection in Netsis NetOpenX REST 2.0.6.9 can be chained into OS command execution, potentially giving an attacker a path to the ERP database host and the financial/accounting data it holds. The advisory says the impact reaches code execution via SQL Server capabilities when the service’s SQL login has sysadmin privileges, with a primary score of 9.8 under that condition (and lower conditional scores of 8.1 and 7.5 under stricter configurations). The issue is described as reachable through the OAuth 2.0 token endpoint, meaning an external attacker could target exposed deployments without credentials and potentially pivot further into the network. No active exploitation has been reported in the source; the disclosure focuses on a tested proof in a reconstructed environment, and no vulnerability identifier has been assigned yet. Recommended actions in the report include applying vendor patches when available, restricting access to the affected endpoint, and implementing input validation to reduce SQL injection risk.
Frequently Asked Questions
What is Citrix NetScaler? Reports say two undisclosed remote code execution zero-days in Citrix NetScaler are being exploited, raising the risk that attackers could take control of exposed ADC and Gateway appliances even before defenders have a CVE to track. In practical terms, a compromise at the edge can quickly turn into disrupted VPN access, application delivery, and authentication services—especially if teams are forced to shut down internet-facing appliances to contain risk.
What is CVE-2025-39964? A critical Linux kernel flaw in the AF_ALG subsystem (CVE-2025-39964) can let a local attacker escalate privileges to root and potentially break out of a Docker container on affected systems. The write-up describes how exploitation can lead to arbitrary command execution as root by manipulating kernel behavior, turning a foothold on one workload into control of the host.
What is Netsis NetOpenX REST 2.0.6.9? A critical unauthenticated SQL injection in Netsis NetOpenX REST 2.0.6.9 can be chained into OS command execution, potentially giving an attacker a path to the ERP database host and the financial/accounting data it holds. The advisory says the impact reaches code execution via SQL Server capabilities when the service’s SQL login has sysadmin privileges, with a primary score of 9.8 under that condition (and lower conditional scores of 8.1 and 7.5 under stricter configurations).

