Posted in

Active Exploits Hit Cisco, Fortinet, Citrix and SharePoint Systems

Five actively exploited vulnerabilities are now pressing against the infrastructure most businesses treat as background plumbing: SD-WAN managers, email gateways, collaboration servers, and remote-access appliances. Cisco Catalyst SD-WAN Manager, Fortinet FortiMail, Microsoft SharePoint Server, and two fresh Citrix NetScaler zero-days have all been confirmed as targets of real-world attacks rather than theoretical research findings. For companies that depend on remote access to run daily operations, the timing is unforgiving.

What "Actively Exploited" Actually Means

A zero-day is a flaw attackers are already using before most organizations have had the chance to patch it. Once the Cybersecurity and Infrastructure Security Agency adds a vulnerability to its Known Exploited Vulnerabilities Catalog, it stops being a theoretical risk and becomes a documented one - exploitation has been observed, not merely demonstrated in a lab. That distinction matters because it changes the calculus for IT teams. Under CISA's BOD 26-04 framework, the highest-risk vulnerabilities can require remediation within three calendar days alongside forensic triage, while others receive 14- or 60-day windows depending on internet exposure and how easily the exploit can be automated. Businesses evaluating their remote-access posture sometimes also look at broader infrastructure questions, including server locations worth knowing about when assessing how traffic and administrative access are routed across regions - a reminder that exposure isn't only about software versions, but about where and how systems are reachable.

The Vulnerabilities Businesses Should Know

CVE-2026-76504 affects Cisco Catalyst SD-WAN Manager, where an unauthenticated attacker can exploit improper URI encoding to bypass authentication and reach the API with administrator privileges - a path to exposing or altering the configurations that connect offices, clinics, stores, and cloud services. CVE-2026-104286 targets Fortinet FortiMail through a path traversal flaw that lets an unauthenticated attacker write arbitrary files to the underlying system, potentially altering configurations or planting a foothold for further compromise. CVE-2026-58644, an older but still relevant Microsoft SharePoint Server deserialization vulnerability, remains dangerous for on-premises farms that a cloud update does not automatically touch. Layered on top are two Citrix NetScaler zero-days: CVE-2026-88771 allows unauthenticated command execution on default configurations, and CVE-2026-88772 is a memory overflow issue that can trigger remote code execution or denial of service when DTLS is enabled - which it is, by default, on NetScaler Gateway VPN virtual servers. Citrix has confirmed exploitation against unmitigated systems and points administrators toward fixed releases such as 14.1-73.37 and 13.1-64.23 or later.

Why a Patch Alone Isn't Proof of Safety

A vendor patch closes a flaw in the software release - it does not confirm that every instance in your environment received it. Clustered nodes miss updates, patch jobs misreport success, forgotten appliances run unsupported versions, and management interfaces sometimes remain exposed to the internet through an overlooked firewall rule. Effective remediation follows three stages: identify affected systems, apply the fix or mitigation, and verify the outcome afterward, including checking logs for signs that exploitation occurred before the patch was applied. For internet-facing gateways and management consoles, waiting for a routine maintenance window can mean treating an active breach as a scheduling inconvenience.

Turning Patching Into a Defensible Response

A sound response starts with confirming whether any of these technologies are in use, checking internet exposure, and verifying exact version numbers rather than trusting product names alone. Logs should be preserved before major changes, since they often provide the only record of what happened before remediation began. Afterward, the running version, service health, and security-control effectiveness all need confirmation - exactly the sequence Cisco recommends for its SD-WAN Manager advisory, which calls for collecting diagnostic data first and checking for indicators of compromise once the upgrade is complete. That order preserves evidence instead of erasing it in the rush to close a ticket.