Dataminr INTEL BRIEF

Implications of Recent Vulnerability Disclosures

Three recent unrelated vulnerability disclosures, a PeopleSoft flaw tied to a ShinyHunters breach of the FBI, a Kiteworks advisory that forced customers offline, and active exploitation of two new Citrix NetScaler CVEs, prove that "apply the patch" is no longer actionable advice once adversaries are already operating pre-disclosure.

Implications of Recent Vulnerability Disclosures
DATE September 29, 2026
AUTHOR Joseph Slowik, Director Threat Research & Cyber Engineering
SHARE
  • Subscribe via RSS
CYBER DEFENSE

Background

In late September 2026, three unrelated vulnerability items with significant implications for enterprise environments were identified:

Since initial reporting, additional information has emerged around each of these items to allow for more measured approaches as well as informed response. Analysis from Google Mandiant (independently confirmed by Dataminr TRACE researchers) identified web application firewall (WAF) and signature evasion techniques as likely culprits for renewed exploitation of CVE-2026-35273 in Oracle PeopleSoft. 

Subsequent Kiteworks analysis indicated the at-risk item in their platform was in use by fewer than 50 organizations (less than 1% of Kiteworks entities), with no known signs of exploitation. Finally, the NetScaler item appears to be of legitimate and ongoing concern, with multiple sources privately indicating active and successful exploitation, leading to Citrix documenting CVE-2026-88771 and CVE-2026-88772 while releasing patches.

While the Kiteworks item resulted in no significant known impact, the nature of the vendor’s advice—to shut off critical, high-availability systems with limited explanation—nonetheless resulted in significant disruption for customer environments. Next, the PeopleSoft exploitation, although apparently based on fuzzing items related to known vulnerability CVE-2026-35273, could be detected and countered, but likely enabled the FBI breach while also facilitating extensive targeting of multiple government, education, and technology organizations globally based on Dataminr TRACE analysis. Finally, the significance of the NetScaler items remains unknown as of this writing, but given the nature of this vulnerability and a reasonable period for adversary weaponization prior to any disclosure of exploitation behaviors or similar, this item will likely result in noticeable impacts.

Aside from all manifesting within the same week, these items share commonalities in terms of limited or imperfect information on critical software or appliances. This has resulted in less than ideal enterprise security and risk response. In each of these instances, “apply the patch” was inactionable and irrelevant advice as adversaries either evaded or operated prior to security updates.

Pre-Patch Defense Emphasis

Defense against exploitation increasingly demands pre-patch actions to minimize attack surface and limit adversary post-exploitation options. As shown below, data supports that time is no longer on the side of defensive decision makers. Reviewing all CVEs issued from September 2025 to September 2026, and mapping the difference between CVE issue date and addition to a known exploited vulnerability (KEV) list (either CISA or VulnCheck), reveals startling developments.

As seen in the above distribution, while the majority of CVE’s issued are added to a KEV list following issuance, a non-trivial number are added immediately or backdated to account for pre-issuance exploitation. This demonstrates a collapse in time-to-patch sequences: while organizations may have historically been able to address items post-CVE and patch release (while waiting for others to reverse engineer the patch to develop exploits), the present shows that defenders and others are now operating behind adversaries from the start.

This immediate trend is further reinforced by events over longer periods of time. As seen below, the time to KEV addition for vulnerabilities has collapsed since 2023 (the CISA KEV was first introduced in late 2022). Removing “backfill” items (vulnerabilities that were known to be under exploitation but added later as KEV was built) shows a clear downward trend in time-to-exploitation when looking at CVE’s issued per year.

As shown by the events discussed earlier, especially the NetScaler activity, waiting for a patch or similar is simply no longer applicable for maintaining a secure network posture. While many vulnerabilities continue to adhere to a classic “release then exploit” pattern, the minority of especially critical items, such as those in external-facing applications or appliances, are frequently dealing with extremely limited patch timescales—or are already being exploited in the wild.

Defense & Visibility

Pre-patch (or more importantly, pre-CVE) exploitation activity against critical systems demands a fundamental change in defensive posture. Instead of adopting a passive aspect related to threats and waiting for risks to manifest then responding to them through post-action controls, organizations must shape the network security landscape in their favor. Indicator alerting and blocking, patch application, and post-event searches for forensic artifacts may satisfy needs related to post-event detection or response, but are simply unsuitable for the current threat landscape.

Instead, organizations must leverage their ownership and management of the network to the greatest extent possible for preventative controls and actions. This includes understanding and mapping attack surface (publicly exposed, or third-party accessible), supplier and partner relationships, and communication dependencies. Only by understanding these routes—which map to adversary dependencies for either initial access or post-compromise command and control—can organizations place themselves in a position to identify and respond to zero days and other similar threats.

Shaping the environment and forcing adversaries to operate within it represents the best possible chance for defenders and decision makers to get ahead of emerging exploitation activity. By adopting secure architecture, policy, and related postures, organizations can minimize the efficacy of system exploitation as a route to compromising the whole network or funnel activity to other, thoroughly monitored pathways (e.g., hardened jump hosts or similar).

Yet there remains a residual risk of adversaries being able to leverage true zero day vulnerabilities for quiet, rapid compromise of victim environments. This could be for rapid data loss, as seen in the PeopleSoft incidents and potentially in a Kiteworks scenario, or for quick pivoting to the internal network as might be the case with NetScaler activity. In these cases, organizations must also plan for worst-case scenarios.

Rapid Mitigation & Recovery

Building a true defense-in-depth posture requires not just preventing incidents, but also the capability and resiliency to weather them when they occur. Given the nature of recent events, this can include the self-imposed denial of critical services, like critical network control items, in order to avoid exploitation while awaiting a patch or mitigations. Learning to operate in a degraded environment is no longer a nice to have, but increasingly a necessary item to ensure operational continuity.

To that end, organizational leadership must grasp the criticality of certain systems in terms of both their potential exposure and the implications of their potential loss. Being able to determine the overall risk equation for certain key systems, like Kiteworks or Citrix NetScalers, can then inform subsequent decisions for security operations and business continuity. Ultimately, the goal is to ensure that the business is able to survive in a contested environment to the best possible degree, including when vital services may be degraded or at risk.

This posture extends to restoration and management: knowing what steps are necessary to not just operate, but also restore critical business systems and evaluate them for possible signs of compromise. Having the restoration, recovery, and potentially forensic skills to engage in these actions, or knowing what external partners can provide them, is a critical step in ensuring the rapid recovery of networks to allow for overall business continuity.

Conclusions

Late September 2026 featured a brutal sequence of potential risks to enterprise environments. While some, such as the Kiteworks situation, appear not to have manifested, others like the vulnerabilities in Oracle PeopleSoft and Citrix NetScaler appear to have been effectively weaponized by adversaries before most organizations were even aware that these were problem areas.

As a result, and as shown in overall vulnerability data over the past year, a defensive posture relying on patching as a primary mitigation mechanism is no longer viable. Instead, organizations MUST leverage all available means to minimize attack surface, ensure visibility on remaining ingress routes to the network, and plan for restoration and recovery for when a breach inevitably occurs.

Throughout this process, organizations must take advantage of all information sources at their disposal. This includes a combination of in-depth analysis of the threat environment, but also real-time indications and warnings of emerging and new activity so that organizations understand when the threat environment shifts in critical ways. Through this informed operating model grounded on security fundamentals and resilience, organizations can move away from a “whack-a-mole” approach to vulnerability management, and embrace an approach allowing for response to entire categories of adversary actions.

2026 Mid-Year Cyber Threat Landscape Report

The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.

Download Report
Sep 29, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Intel Brief