Actively Exploited NetScaler and Exchange Flaws Put School Edge Infrastructure at Risk
CISA adds exploited Citrix NetScaler CVE-2026-88779 to KEV; Microsoft patches Exchange CVE-2026-96940; WordPress plugin XSS exploited. K-12 guidance.
- CISA added CVE-2026-88779 (CVSS 8.7), a memory overflow in Citrix NetScaler ADC and Gateway, to its Known Exploited Vulnerabilities catalog after Citrix confirmed targeted zero-day attacks that can crash appliances and knock SAML single sign-on offline.
- Microsoft released out-of-band Exchange Server updates for CVE-2026-96940, a high-severity flaw letting an authenticated attacker read other users' mail and attachments within the same organization.
- Separately, stored XSS in the WordPress plugins Ninja Forms and WPC Product Bundles for WooCommerce is being exploited to plant backdoors and create rogue administrator accounts; no CVE identifiers were available at reporting time.
What to do now
- Inventory every Citrix NetScaler ADC and NetScaler Gateway instance, record its version and internet exposure, then apply the latest Citrix security updates as an emergency change. If patching is not immediately possible, restrict management interfaces to trusted internal networks or VPN-only access and enable Citrix's recommended mitigations.
- Apply Microsoft's out-of-band Exchange Server update for CVE-2026-96940 to all servers, prioritizing internet-facing and hybrid deployments, then verify the installed build and restart services as required.
- Hunt for exploitation on both platforms: NetScaler logs for crashes, memory exhaustion, unexpected restarts and SAML authentication anomalies; Exchange logs for unusual same-organization mailbox and attachment access. Rotate credentials, tokens, certificates and secrets that transited or were stored on affected appliances.
- Update the Ninja Forms and WPC Product Bundles plugins, audit WordPress for unauthorized administrator or editor accounts, remove them, rotate admin passwords and salts, and scan mu-plugins, uploads, wp-config.php, cron events and database options for backdoors.
- Prepare continuity before you need it: configure a SAML fallback or manual authentication path, document manual traffic redirection, test backups and restoration, and report any confirmed compromise to your security team and privacy office.
Related items
- Ninja Forms plugin flaw exploited to hack WordPress sites
- U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog
- CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
- CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
- Citrix NetScaler security snafus get even worse amid more 0-day reports
- Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)