Citrix NetScaler zero-days and a WordPress core flaw hit CISA's exploited list, while ShinyHunters bypasses WAFs on Oracle PeopleSoft

CISA KEV adds a WordPress core flaw and Citrix NetScaler zero-days; ShinyHunters bypasses WAFs to exploit Oracle PeopleSoft. Patch or isolate now.

  • CISA added a WordPress Core flaw (CVE-2026-87902, CVSS 9.2) to its Known Exploited Vulnerabilities catalog and amplified eight Citrix NetScaler ADC/Gateway CVEs (CVE-2026-88771 to CVE-2026-88778); Citrix confirmed two of them were exploited as zero-days before patches existed.
  • Attackers linked to the ShinyHunters extortion gang are using a URL-encoding trick to bypass WAF rules and exploit Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8), then drop web shells on vulnerable servers.
  • Impact for schools and government: internet-facing remote-access appliances, ERP/HR systems and public websites are the targets — expect credential theft and web shells if you are unpatched or exposed.

What to do now

  1. Inventory today: list every internet-facing Citrix NetScaler ADC/Gateway appliance, every WordPress site you host, and any Oracle PeopleSoft (or similar ERP) instance reachable from the internet. Record versions and owners.
  2. Patch first, isolate second: apply Citrix, WordPress and Oracle fixes as soon as they are available. Where no patch exists yet, take the appliance offline or block external access, and restrict management interfaces to trusted networks with MFA.
  3. Fix the WAF gap: normalize and decode URL-encoded input before rule matching, test whether encoded payloads reach PeopleSoft endpoints, and add custom rules for the known bypass pattern. Do not treat an existing WAF rule as proof of protection.
  4. Hunt for compromise: review web, application and firewall logs for file-inclusion attempts, encoded requests, new admin accounts, unexpected processes, web shells in web directories, and anomalous outbound connections from NetScaler and PeopleSoft hosts.
  5. Rotate and recover: after patching, rotate all credentials, API keys and certificates that lived on or transited affected systems; preserve logs, run a compromise assessment, and follow your incident response plan before restoring service.

Related items