Attackers using two NetScaler zero-days since early September left webshells that patching to 14.1-73.37 or 13.1-64.23 does not remove. Operators have to search every appliance for those traces, patched or not, and move OT remote access onto a jump host of its own.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
LevelBlue says attackers are exploiting NetScaler flaw CVE-2026-88771, rated 9.5, to create a hidden superuser account and plant web shells. The patch closes the injection but removes neither, so already-exposed appliances need a compromise check.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence60
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74
SonicWall confirmed both SMA1000 flaws were exploited before disclosure, and CISA gave federal agencies three days to remediate. The lower-scored console bug is the step that reaches the operating system.
Reality
- Evidence55
- Adoption60
- Hype gap+8
- Incentives35
- Confidence48
FortiGuard Labs says Evooo1Bot packs SOCKS5 relaying, credential sniffing, SSH spreading and 16 flood modes into one binary across 12 CPU architectures. The tunnel matters more than the flood.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence42