Published: 10/05/26
Monday opens on a gateway you may have patched last week. Citrix shipped another NetScaler build Sunday for a SAML memory bug already in use, and the federal due date is Wednesday. Also on the desk: Zammad’s help-desk bugs are due today if you are still on 6.5, Dell’s Kubernetes storage modules can hand out array admin credentials with no login, and a self-hosted GitLab AI gateway can run commands from a custom flow. (If FortiMail management is still on the internet, Friday’s workaround is still the control — fixed builds were still upcoming over the weekend.)
Lead Story
Your NetScaler gateway needs another build before Wednesday
CVE-2026-88779 is a memory overflow on customer-managed NetScaler ADC and Gateway when the box is a SAML service provider or identity provider. Citrix calls it denial of service. CISA added it to KEV on Sunday, due Wednesday, October 7. The late-September builds for CVE-2026-88771 and CVE-2026-88772 do not close it. Move to 14.1-73.41 or 13.1-64.28, and hunt crash loops before you upgrade.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: The remote-access edge is the blast radius, and “we patched NetScaler” is how this one gets skipped.
Also Worth Your Attention
Zammad 6.5 has a due date of today
CVE-2026-102489 is a session hijack to code execution on Zammad 6.5 and older. CVE-2026-102490 is the local privilege bug CISA says can chain to root; the vendor says that one is not remote by itself and is still being fixed. Move to 7.2.0 and keep the host off the internet.
Why it matters: The help desk holds the mail and the tokens. Unsupported 6.x is the line that is actually exploitable remotely.
Dell storage modules can skip the login
CVE-2026-63688 and CVE-2026-63692 are missing-authentication bugs in Dell Container Storage Modules, scored 10.0. An unauthenticated caller can pull array admin credentials. A related bug reaches root on Kubernetes nodes. Upgrade to 1.18.0 and rotate JWT secrets and array passwords.
Why it matters: The CSI driver is the path to the volumes, not a side component.
Self-hosted GitLab AI gateways need their own image tag
CVE-2026-90970 lets a Duo Agent Platform user escape a custom-flow template and run commands on a self-hosted AI Gateway. Fixed gateway tags are 19.2.4, 19.3.2, and 19.4.1. GitLab.com, Dedicated, and GitLab-hosted gateways are already done.
Why it matters: The box you stood up so prompts stay in-house is the one with the signing keys.
Slack paste: Monday brief — NetScaler SAML needs 14.1-73.41 or 13.1-64.28 before Wed Oct 7 (last week’s build does not count, CVE-2026-88779); Zammad to 7.2.0 today if you are on 6.5 (KEV due Oct 5); Dell CSM to 1.18.0 and rotate secrets; self-hosted GitLab AI Gateway to 19.2.4 / 19.3.2 / 19.4.1. FortiMail management still needs Friday’s workaround if it is on the internet.
Go Deeper
Identity & Access Management → · Cybersecurity Tools →
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.