Citrix spent Monday’s news cycle explaining away a mystery. Administrators who had patched NetScaler’s two confirmed zero-days were reporting appliances that kept rebooting after the fix went in, and nobody had a clean answer for why. By Wednesday, Citrix had one: CVE-2026-88779, a CVSS 8.7 memory overflow in SAML SP/IdP configurations, was a third zero-day the whole time, and attackers had been using it to crash unmitigated appliances before any patch existed at all. CISA added it to the Known Exploited Vulnerabilities catalog on October 4 with a remediation deadline of October 7, which has already passed as of this writing. Citrix shipped NetScaler 14.1-73.41 and 13.1-64.28 on October 5.
Three actively exploited zero-days in the same product line inside two weeks is not a bad patch cycle. It’s a sign that the vendor and its customers were both behind the attacker the entire time, discovering new holes by watching symptoms rather than by finding bugs before anyone could use them.
Patching the hole doesn’t evict the tenant
Monday’s report carried the detail that matters most here, and it’s worth restating because it changes what “patched” means for this incident: Mandiant found dozens of confirmed NetScaler compromises with web shells planted for persistence, and those web shells survive the patch. Exploitation on the first two flaws traces back to early September, more than three weeks before Citrix issued any warning. An organization that patched NetScaler last week closed the front door an attacker already walked through weeks earlier, and the appliance’s own vendor-side detection has no particular reason to surface a web shell that was dropped before the patch existed to describe it.
This is the actual lesson of the NetScaler sequence, and it’s not about NetScaler specifically. Edge appliances, SSL VPNs, and SAML gateways are privileged, internet-facing, and typically excluded from the EDR coverage that would catch a web shell on a regular server. When a vendor confirms active exploitation going back weeks, “did we patch” is the wrong question. “Did we hunt for persistence on every instance that was internet-facing during the exposure window” is the right one, and it’s a much more expensive question to answer honestly. Most organizations will not ask it, because the patch ships, the KEV deadline closes, and the ticket gets marked resolved.
The SAML angle on CVE-2026-88779 adds a second wrinkle. SAML SP/IdP configurations are disproportionately deployed on exactly the NetScaler instances doing the heaviest lifting: federated authentication for external-facing applications, often the ones an organization cares most about keeping available. Attackers used this flaw to crash appliances before a patch existed, which means availability was the visible symptom while reconnaissance or persistence may have been the actual objective. Crashing a system is a strange thing to do if denial of service is the goal in itself; it’s a much more useful thing to do if you want administrators focused on an outage instead of an intrusion.
The same mistake is happening in AI inference infrastructure, three years compressed into one
On October 7, JFrog disclosed CVE-2026-105192, a CVSS 9.8 unauthenticated remote code execution flaw in LMCache, open-source caching middleware that speeds up vLLM and other LLM inference servers. The bug is almost nostalgic in its simplicity: multiprocess mode opens an unauthenticated ZeroMQ port that deserializes attacker-controlled data using Python’s pickle module before validating what kind of message it even received. On LMCache’s official container images, the process that does this runs as root. No patched release exists as of disclosure, and the flaw spans every stable release from 0.3.9 through 0.5.5 plus the current release candidate.
Unauthenticated deserialization of attacker-controlled data was a top-tier finding in Java and .NET middleware a decade ago, and the industry spent years building the muscle memory to avoid it: validate before you deserialize, never trust the wire format, don’t run network-facing processes as root. LMCache’s maintainers inherited none of that muscle memory, because the AI inference stack is new enough that the people building it are solving performance problems, not replaying old CVE databases. This is the pattern to watch across the AI infrastructure layer generally: vLLM itself disclosed two more issues this week, a tensor validation gap in the disaggregated scale-out path (CVE-2026-105754, patched in 0.30.0) and an out-of-bounds read in the Mamba mixer component (CVE-2026-105775, no patch confirmed, publicly disclosed, project unresponsive to the original report). None of these are exotic. They’re the same bug classes traditional web middleware already paid for in breaches, arriving in software that didn’t exist three years ago and is now load-bearing for every organization running self-hosted LLM inference.
The defender gap here is specific: security teams built playbooks for patching Java, patching Python web frameworks, patching container runtimes. Very few have an inventory of which inference servers are running LMCache, in multiprocess mode, with which container image, exposed to which network segment. That inventory gap is the actual vulnerability. A CVSS 9.8 with no patch means the only real mitigation is knowing the asset exists and firewalling the ZeroMQ port, and that only works if someone already mapped the deployment.
What changed since Monday
Two items from Monday’s report moved materially. The NetScaler reboot mystery is now a confirmed third zero-day, as covered above, which upgrades this from an unexplained operational nuisance to a third entry in an active-exploitation timeline that federal agencies are now required to remediate under an already-lapsed KEV deadline. Separately, the KillSec story escalated past what Monday captured. Monday reported a single arrest: Spanish police detaining a 16-year-old as the alleged operator. By September 30, Operation KillSwitch, led by Germany’s Hamburg State Criminal Police Office with Europol and Eurojust support, had seized KillSec’s leak site, five central servers, and more than 110 terabytes of stolen extortion data, searched eight properties across Spain, Greece, Romania, and the UK, and provisionally arrested three suspects. Investigators tied the group to roughly 1,000 attempted attacks with about 500 successful. KillSec no longer has infrastructure to extort anyone with, which is a materially different outcome than one teenager in custody.
What to watch
Watch whether exploitation of Atlassian’s CVE-2026-21589, a CVSS 9.3 unauthenticated path-traversal flaw across eight on-premises products, spreads from opportunistic scanning into targeted follow-on access before Data Center customers who can’t patch immediately get WAF rules in place; honeypot detection within hours of the technical writeup going public is the kind of signal that precedes a broader wave, not a contained one. Also watch for a patched LMCache release and, more importantly, for any confirmed exploitation in the wild before that release ships; a CVSS 9.8 unauthenticated RCE with a one-week-old disclosure and no fix is exactly the kind of gap that gets used quietly before it gets used loudly.
Security Unlocked publishes threat intelligence and strategic analysis twice weekly. This mid-week brief covers developments from October 5, 2026 through October 8, 2026.
Security