Decrypted: The UK Cyber Briefing
Sep 30, 2026 · 5 min · 6 segments
Citrix has patched its two NetScaler zero-days, the NCSC has issued an alert, and Mandiant has described the web shells left behind. Patching is not enough, so the advice is to hunt and rebuild. Plus…
Two of them are being exploited.
CVE-2026-88771 lets an unauthenticated attacker run commands.
CVE-2026-88772 is a memory overflow that can give code execution or a crash when DTLS is enabled.
It says affected builds are fourteen point one before fourteen point one dash seventy-three point three seven, and thirteen point one before thirteen point one dash sixty-four point two three.
Mandiant says attacks on organizations in North America and Europe began in early September.
That's well before any patch existed.
Counts of exposed appliances differ.
Census reported forty-two thousand seven hundred and thirty-five vulnerable hosts.
Two of them are being exploited.
CVE-2026-88771 lets an unauthenticated attacker run commands.
CVE-2026-88772 is a memory overflow that can give code execution or a crash when DTLS is enabled.
It says affected builds are fourteen point one before fourteen point one dash seventy-three point three seven, and thirteen point one before thirteen point one dash sixty-four point two three.
Mandiant says attacks on organizations in North America and Europe began in early September.
That's well before any patch existed.
Counts of exposed appliances differ.
Census reported forty-two thousand seven hundred and thirty-five vulnerable hosts.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.