Security Advisory
This Week's Top 4: A New Citrix NetScaler SAML Flaw, AhsayCBS Backup Servers Under Attack, a Critical SonicWall SMA 1000 Fix, and More
Citrix disclosed a second SAML flaw in NetScaler that moves the builds to target again, attackers compromised AhsayCBS backup servers before Ahsay shipped a corrected hotfix, SonicWall fixed a CVSS 10.0 flaw in its SMA 1000 remote-access appliances with no workaround, and CISA confirmed exploitation of five long-patched server flaws in a single day. Here are the four verified developments for small and mid-size businesses this week, ranked by relevance, exploitation evidence, and urgency.
This brief covers verified security and compliance developments from Sunday, October 4 through Saturday, October 10, 2026, with a research cutoff of Sunday, October 11, 2026 at 11:00 a.m. Central. It is the edition for the regular Sunday, October 11 slot. Remote-access gateways dominated the week: Citrix disclosed a further NetScaler flaw in the same SAML sign-in component as the one CISA added to its Known Exploited Vulnerabilities (KEV) catalog on October 4, SonicWall fixed a maximum-severity flaw in its SMA 1000 appliances, and attackers began compromising AhsayCBS, a backup server platform used by managed service providers. CISA also confirmed active exploitation of five server flaws that were fixed years ago.
Executive Summary and Priorities
Four verified developments met our bar for inclusion this week. We did not pad the list to reach five:
- Citrix NetScaler ADC and Gateway
- a new SAML flaw, CVE-2026-107406, means the builds that fixed the October 4 KEV entry are not the end of the story for appliances acting as a SAML Identity Provider. The builds to target are now 14.1-73.46 or 13.1-64.29, or 14.1-73.46 FIPS or 13.1-37.283 for FIPS and NDcPP editions.
- AhsayCBS backup servers
- attackers chained two flaws to take over AhsayCBS servers starting October 7, and on October 10 Ahsay said its earlier fix was incomplete and released the v10.3.4.45 hotfix.
- SonicWall SMA 1000
- a CVSS 10.0 pre-authentication flaw in the remote-access portal, fixed October 6, with no workaround. SonicWall reported no evidence of exploitation at release; a security firm later reported attempts against its honeypots.
- Five older server flaws
- CISA added ProFTPD, ONLYOFFICE Docs, Apache Struts, ISC BIND, and Strapi vulnerabilities to its KEV catalog on October 8, confirming that attackers are using flaws that were fixed between 2015 and 2023.
How We Ranked This Week's Developments
We ranked these by how many of the businesses we serve are likely to run the affected technology, the strength of the exploitation evidence (a vendor's own confirmation, a CISA KEV listing, or both), how directly the affected system is reachable from the internet, and how much time remains before a deadline or consequence lands. Citrix ranks first because NetScaler is a common remote-access and single sign-on gateway, CISA has confirmed exploitation in the same component, and the fix target changed during the week. AhsayCBS ranks second because exploitation is confirmed first-hand by an incident response firm, it sits in the backup layer many managed service providers run for their clients, and the vendor's first fix proved incomplete. SonicWall ranks third: its severity score is the highest of the week, but exploitation is not confirmed, and SonicWall's firewalls and SMA 100 appliances are not affected. The KEV batch ranks fourth because exploitation is confirmed but the affected software is old and less often run directly by small businesses. These rankings are editorial judgments, not a measured risk score.
1A New Citrix NetScaler SAML Flaw Moves the Builds to Target Again
On October 8, 2026 Citrix published security bulletin CTX697191 for CVE-2026-107406, which Citrix's bulletin rates CVSS v4.0 9.5 and describes as a "memory overflow vulnerability leading to Remote Code Execution or Denial of Service." It only affects an appliance configured for SAML sign-in. An appliance acting as a SAML Identity Provider is affected on builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28, inclusive, plus the matching FIPS and NDcPP builds; an appliance acting as either a SAML Service Provider or Identity Provider is affected on builds before 14.1-73.37 and 13.1-64.23. The fixed releases are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-73.46 FIPS and later, and 13.1-37.283 and later for 13.1-FIPS and 13.1-NDcPP. Citrix's bulletin does not state that this flaw has been exploited, and it was not in CISA's KEV catalog as of the catalog's October 8 release.
It matters because of what came just before it. CISA added CVE-2026-88779, a denial-of-service flaw in the same SAML component, to its KEV catalog on October 4 with an October 7 due date, and the build that fixed it, 14.1-73.41, falls inside the new flaw's affected range for Identity Provider appliances, as our advisory on CVE-2026-88779 now explains. On October 9, CISA also updated its alert on the NetScaler zero-days to warn that in unpatched deployments "cyber threat actors may also exploit CVE-2026-88779 to force a reboot" that can "allow execution of code previously injected through exploitation of CVE-2026-88771," one of the two zero-days disclosed on September 27 that we covered at the time. That turns a denial-of-service flaw into one step of a compromise on an appliance that was already exposed.
Who is affected: businesses that run their own NetScaler ADC or NetScaler Gateway, usually for remote access or for single sign-on into business applications. Citrix's bulletins apply only to customer-managed appliances; Citrix updates its own Citrix-managed cloud services. Who is not affected: an appliance that does not use SAML is outside both SAML flaws, though it still needs the September 27 fixes. What to do: before changing an appliance that has been reachable from the internet, preserve its logs and run the indicator-of-compromise check Citrix provides through NetScaler Console, as CISA recommends, then move to 14.1-73.46 or 13.1-64.29 or later; FIPS and NDcPP editions need 14.1-73.46 FIPS or 13.1-37.283 or later instead. Confirm your identity provider issues signed SAML assertions before upgrading, because our CVE-2026-88779 advisory describes how the fixed builds stop accepting unsigned ones, and test sign-in right after the upgrade.
2Attackers Are Compromising AhsayCBS Backup Servers
Huntress reported on October 8, 2026 that, starting October 7 at 23:20 UTC, it observed attackers exploiting two AhsayCBS flaws together, per Huntress's write-up. CVE-2026-105133 is an authentication flaw in the product's API, and CVE-2026-105134 is a flaw in the Replication Receiver's UpdateReceivers.do endpoint that Huntress says allows unauthenticated remote code execution as SYSTEM. The CVE records rate them CVSS v3.1 7.3 and 10.0, per the National Vulnerability Database. Huntress counted five targeted organizations as of October 8 and found JSP webshells in the AhsayCBS web directory, a malicious replication receiver, and a cryptocurrency miner disguised as Microsoft Edge.
The fix changed during the week. The CVE records, published October 4 by VulDB as the assigning authority, list AhsayCBS up to 10.3.2 as affected and say upgrading to 10.3.4 resolves the issue, per NVD's record for CVE-2026-105133, and Ahsay said on October 9 that v10.3.4.0 addressed both flaws. Huntress's October 8 update said 10.3.4 was also affected. On October 10, Ahsay's Critical Security Alert, posted on Ahsay's announcement, confirmed that "our previous patch v10.3.4.0 did not fully address" CVE-2026-105133 and CVE-2026-105134 and told partners running affected v10 versions to apply the AhsayCBS v10.3.4.45 hotfix, available through Ahsay's partner portal, and then reboot the server. Ahsay's October 9 note also said an upgrade does not resolve problems from a compromise that happened before it.
Who is affected: AhsayCBS is the server side of the Ahsay backup platform, typically run by managed service providers and system integrators to hold their clients' backups, so a business may depend on it without knowing it. What to do: if you or your backup provider run AhsayCBS, apply the v10.3.4.45 hotfix and reboot, as Ahsay directs; v10.3.4.0 alone is not enough. Restrict the management interface and Replication Receiver to trusted IP addresses or a VPN, check for the indicators of compromise Huntress published, and re-image any host that shows them from a trusted backup, as Huntress advises, because the hotfix does not remove an attacker who is already in. If a provider holds your backups, ask whether they use AhsayCBS and whether they have applied v10.3.4.45.
3SonicWall Fixes a CVSS 10.0 Flaw in SMA 1000 Remote-Access Appliances
SonicWall published advisory SNWLID-2026-0017 on October 6, 2026, fixing four vulnerabilities in its SMA 1000 Secure Mobile Access appliances, per SonicWall's security advisory. The most serious, CVE-2026-102255, is a pre-authentication server-side request forgery flaw in the appliance's Work Place interface, which SonicWall rates CVSS 10.0 and says could let "a remote unauthenticated attacker" direct the appliance "to issue requests on their behalf and reach internal functionality and perform unauthorized operations." The other three, CVE-2026-102256, CVE-2026-102257, and CVE-2026-102258, require an authenticated administrator and are rated 7.8, 7.2, and 5.5.
Affected are SMA 1000 models 6210, 7210, and 8200v on version 12.4.3-03526 (platform-hotfix) and older, and 12.5.0-02952 (platform-hotfix) and older; SonicWall directs customers to the latest platform hotfix on MySonicWall. SonicWall states that no workaround is available and that "there is currently no evidence any of the vulnerabilities addressed in this release are being exploited in the wild." That was the status at release. On October 9, Previdian founder Ryan Dewhurst told BleepingComputer that Previdian's honeypots had logged requests consistent with attempts to exploit CVE-2026-102255, while saying Previdian had not established whether those attempts would have compromised any systems. Treat that as early warning, not confirmed exploitation. SonicWall states that the flaws do not affect the SMA 100 series or SSL-VPN running on SonicWall firewalls.
Why an SMB should care: an SMA 1000 is the front door for remote employees, and an unauthenticated flaw in that front door is worth closing before exploit details circulate, not after. What to do: if your business or your IT provider runs an SMA 1000 appliance, confirm its version and apply the platform hotfix now, without waiting for confirmed exploitation. If you are not sure which SonicWall product you have, ask your provider; a firewall or SMA 100 does not need this update.
4CISA Confirms Exploitation of Five Long-Patched Server Flaws
On October 8, 2026 CISA added five vulnerabilities to its KEV catalog, each with an October 11 due date for federal agencies, per CISA's Known Exploited Vulnerabilities catalog. None is new; what is new is CISA's confirmation that attackers are using them now:
- ProFTPD (CVE-2015-3306)
- the mod_copy module in ProFTPD 1.3.5 lets an unauthenticated attacker read and write arbitrary files through the SITE CPFR and SITE CPTO commands, rated CVSS 10.0 in the National Vulnerability Database.
- ONLYOFFICE Docs (CVE-2021-3199)
- a path traversal in Document Server before version 5.6.3, when JWT is used, that can lead to remote code execution, rated 9.8 per NVD.
- Apache Struts (CVE-2016-3081)
- remote code execution when Dynamic Method Invocation is enabled, affecting Struts 2.3.20 through 2.3.28 except 2.3.20.3 and 2.3.24.3, per Apache's S2-032 bulletin, which lists 2.3.20.3, 2.3.24.3, and 2.3.28.1 as fixed and disabling Dynamic Method Invocation as the workaround; rated 8.1 per NVD.
- ISC BIND (CVE-2015-5477)
- a crafted TKEY query crashes the named DNS server in BIND 9.1.0 through 9.8.x, 9.9.0 through 9.9.7-P1, and 9.10.0 through 9.10.2-P2, per ISC's advisory, which names 9.9.7-P2 and 9.10.2-P3 as the patched releases; rated 7.5 per NVD.
- Strapi (CVE-2023-22894)
- Strapi 3.2.1 up to, but not including, 4.8.0 can leak user email addresses, password hashes, and password reset tokens through filters on private fields, and the researcher showed it can be exploited without logging in, per Strapi's security disclosure, which names 4.8.0 as the fix; chained with CVE-2023-22621 it allows unauthenticated remote code execution on Strapi 4.5.5 and older, and CISA notes the same chain.
Who is affected: few small businesses run these directly, but they turn up in places nobody inventories: an FTP server or network storage device that ships ProFTPD, a self-hosted document editing server, an older line-of-business web application built on Struts, an in-house DNS server, or a website built on Strapi by an outside developer. Fixes for all five have existed for years, so an exposed system is one that has not been updated in a very long time, which makes it worth asking whether it should still be running at all. What to do: ask your IT provider, website developer, and hosting provider to confirm in writing that none of these versions are running on your behalf, and retire or upgrade any that are. CISA flags four of the five entries, all but BIND, for forensic triage, so if you find an affected version that has been reachable from the internet, preserve its logs and check for signs of compromise before you upgrade or retire it; closing the vulnerable path does not remove an attacker who already used it.
Also This Week: GhostAction Credential Theft on GitHub
On October 8, attackers using stolen maintainer accounts pushed a workflow file into hundreds of GitHub repositories that collects GitHub Actions secrets and scans the repository history for cloud, AI service, and other credentials, then sends them to an external server, per Socket's analysis, which later counted more than 500 affected accounts. We did not rank it because it affects businesses that build or publish software on GitHub, not the technology most of the businesses we serve run day to day. If your business or a developer you work with keeps code on GitHub, follow Socket's guidance: remove any unfamiliar workflow file, rotate every secret the affected repository uses and any credential that ever appeared in its history, and require phishing-resistant MFA on developer accounts.
Update on a Prior Item: Citrix NetScaler Zero-Days
Our September 27 brief flagged the NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 as developing after its coverage window and said we would rank them in the following week's brief. That October 4 edition was not published, so this item closes the loop: those zero-days were followed by CVE-2026-88779 on October 3 and CVE-2026-107406 on October 8, and CISA's October 9 update ties the first SAML flaw to the earlier zero-day. Item 1 above is the current state of that story.
Do Now
- If your business runs Citrix NetScaler ADC or Gateway with SAML sign-in, preserve logs, run Citrix's indicator-of-compromise check, and upgrade to 14.1-73.46 or 13.1-64.29 or later (14.1-73.46 FIPS or 13.1-37.283 for FIPS and NDcPP editions).
- If you or your backup provider run AhsayCBS, apply Ahsay's v10.3.4.45 hotfix and reboot, restrict the management interface and Replication Receiver to trusted addresses or a VPN, and check Huntress's indicators of compromise.
- If your business runs a SonicWall SMA 1000 appliance, apply the platform hotfix from MySonicWall now.
- Ask your IT provider, website developer, and hosting provider to confirm none of the five October 8 KEV versions are running on your behalf.
Plan Next
- Add remote-access gateways, file transfer servers, network storage, and developer-built websites to your patch inventory, not just laptops and servers.
- Ask your IT provider how quickly a critical gateway fix is applied once released, and whether that includes appliances a vendor or partner manages for you.
- Retire software that has gone years without updates rather than trying to keep it patched.
Watch List
- Whether Huntress or Ahsay report exploitation that the v10.3.4.45 hotfix does not stop.
- Whether CISA adds CVE-2026-107406, the AhsayCBS flaws, or the SonicWall SMA 1000 flaws to its KEV catalog.
- Whether Citrix publishes further NetScaler SAML fixes or new indicators of compromise.
- Microsoft's October security updates, scheduled for Tuesday, October 13.
The Bottom Line
This week's common thread is infrastructure nobody looks at. Two of the four items are remote-access gateways, the systems every remote employee connects through, one is the backup server a provider may run on your behalf, and the last is a reminder that attackers keep using flaws that were fixed long ago because forgotten systems never received the fix. This brief is general security awareness, not a HIPAA, FTC Safeguards, or cyber-insurance compliance service. Cyber One Solutions helps commercial businesses keep those gateways patched and watched through managed cybersecurity, and finds the forgotten servers and appliances through IT and security assessments. If you are not sure where to start, our free cybersecurity risk score is a quick way to see which of this week's gaps may apply to you.
Sources
- Citrix Security Bulletin CTX697191: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-107406
- Citrix Security Bulletin CTX697174: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-88779
- CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (updated October 9, 2026)
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-88779
- Huntress: Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
- Ahsay Announcements: Critical Security Alert for CVE-2026-105133 and CVE-2026-105134 (October 10, 2026)
- NIST National Vulnerability Database: CVE-2026-105133
- NIST National Vulnerability Database: CVE-2026-105134
- BleepingComputer: Max severity SonicWall SMA1000 flaw now exploited in attacks
- Socket: GhostAction Expands to Cloud and AI Credentials
- SonicWall Security Advisory SNWLID-2026-0017: SMA1000 Series Appliances Affected By Multiple Vulnerabilities
- CISA Known Exploited Vulnerabilities Catalog
- NIST National Vulnerability Database: CVE-2015-3306
- NIST National Vulnerability Database: CVE-2021-3199
- NIST National Vulnerability Database: CVE-2016-3081
- NIST National Vulnerability Database: CVE-2015-5477
- NIST National Vulnerability Database: CVE-2023-22894
- ISC Knowledge Base AA-01272: CVE-2015-5477, An Error in Handling TKEY Queries Can Cause named to Exit
- Apache Struts Security Bulletin S2-032
- Strapi: Security Disclosure of Vulnerabilities CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
