Skip to content
category — security

ls ./category/security

Security

Breaches, vulnerabilities, malware and the patches that matter.

212 articles

The host key check ran, and passed, on a curve the attacker chose for it

2026-10-08

wolfSSH never verified that the elliptic curve in a server's host key matched the algorithm both sides had just negotiated. A machine-in-the-middle could swap in a key on a different curve, sign with its own private key, and be accepted with no error. Fixed in 1.6.0 — and it needs one more condition that is common in embedded code.

The NetScaler appliances restarting after the patch were not a patch bug — they were a third zero-day, and the sixth crash is the trigger

2026-10-06

On 3 October we wrote that Citrix customers were watching their gateways reboot after installing the emergency build, with no CVE and no root cause published. Citrix disclosed it on the 4th: CVE-2026-88779, a memory overflow reached through SAML, exploited in targeted attacks. Each attempt crashes the authentication service, and the sixth restarts the appliance.

The NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it

2026-10-03

Citrix shipped 14.1-73.37 for two actively exploited 9.5s. Customers who installed it are reporting repeated appliance reboots, traced to crafted SAML traffic crashing the authentication service until the watchdog restarts the box. Citrix says it is tracking a newly seen SAML issue. Bulletin CTX697096, last updated 27 September, still does not mention it.