An internet caller can reach an affected NetScaler virtual server without credentials.
Citrix confirms exploitation of both paths on unmitigated deployments.
Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery, VPN, and remote-access appliances
Unauthenticated remote code execution on an enterprise perimeter gateway
The change is current exploitation: a caller without credentials can now cross a deliberately deployed perimeter boundary through either of two code-execution paths.
Internet reachability to an affected virtual server is sufficient; CVE-2026-88772 additionally needs DTLS, which is enabled by default on VPN virtual servers.
CVE-2026-88771 reaches attacker-controlled commands through improper input validation, while CVE-2026-88772 reaches code execution through a DTLS memory overflow.
Citrix says both flaws are being exploited on unmitigated systems.
Fixes are available, but complete revocation of pre-fix NetScaler images has not been established.
Apple iOS and iPadOS devices whose background photo-processing services automatically decode EXR attachments received through iMessage.
The decoder allocates 12 bytes per RGB pixel and writes 16 attacker-controlled bytes, after Messages and the photo subsystem route the unopened attachment into libAppleEXR.
The researcher reached arbitrary write and program-counter control in a harness, but did not demonstrate clean cross-process code execution because the remaining path requires a PAC-signed pointer.
Apple has fixed the ImageIO flaw.
WordPress Core, the PHP content-management system used by public websites.
A valid page_id and double-encoded traversal can make template resolution include readable PHP outside the active theme.
Code execution additionally requires a qualifying theme layout, a usable local inclusion target, PEAR, and register_argc_argv; under those conditions pearcmd.php can write PHP that a second request executes as the web-server account.
WordPress has published a fix.
Authlib, a cross-platform Python library used by web applications and microservices for OAuth, OpenID Connect, JWT and JWS handling.
The general-JSON deserializer begins in a successful state and performs no verification loop iteration when signatures is empty, so it returns an unsigned payload as verified.
A relying application can turn that result into forged identities, roles, scopes, inter-service messages, or configuration.
Public code demonstrates the bypass, no patch is available in the reviewed material, and we do not know how commonly applications expose this Authlib path.
Wikipedia for Android, the Wikimedia reading application running on Android phones and tablets.
Suffix-only hostname and cookie checks accept a domain such as evil-wikipedia.org, load it in the app's WebView, and attach Wikimedia cookies.
The attacker receives the username, long-lived token, and session token, which permit account takeover across Wikimedia projects.
The user must already be logged in and click the supplied wikipedia:// link.
Zimbra Collaboration Suite mail and collaboration servers with OnlyOffice or Document Editing available.
An anonymous caller needs the URL of an existing supported public document on a server with OnlyOffice or Document Editing enabled.
Unsigned save fields permit path-traversal writes outside the document location, producing command execution under the zimbra service identity.
Zimbra has published a fix.
PHP-FPM, the FastCGI process manager shipped with PHP on Unix-like web servers.
The check compares only 12 of 16 address bytes, so a nearby IPv6 host can pass listen.allowed_clients and submit FastCGI requests to accessible PHP scripts.
Exposure requires an IPv6-reachable TCP listener and an attacker address sharing the configured client's first 96 bits; patched releases exist for every supported branch.
FreeRDP, an RDP client/server implementation and toolkit on Linux and other Unix-like systems.
Under a common 022 umask, private-key files could inherit permissions broad enough for another user on a shared Unix host to read an active temporary copy or traversable output file.
Generated PFX output could also use a public default password.
FreeRDP has published fixes for the affected workflows.
WatchGuard AP wireless access points running WatchGuard AP software.
The management API contains command injection, while a separate access-control flaw can issue a valid API session without credentials.
The practical boundary is API reachability: the caller must be able to connect to the access point's internal service.
WatchGuard has published corrected firmware.
WeKan, a self-hosted collaborative kanban server commonly deployed in containers.
REST login ignored loginDisabled, and existing bearer or cookie tokens remained usable after an administrator disabled the identity.
The reporter and maintainer verified corrected revocation behavior before release.
OpenCode, a cross-platform local coding-agent server and web interface.
A top-level text/plain form navigation avoids a CORS preflight and supplies a remote package URL to the local upgrade endpoint.
npm, pnpm, or Bun then installs the package and executes its lifecycle script as the OpenCode user; cached Basic credentials can preserve the path even when the server is password protected.
The corrected release rejects the reproduced request with HTTP 415 and limits upgrade targets to semantic versions.
Rejetto HTTP File Server 2.x, a Windows file-sharing web server.
The filename enters a rejected-upload response, survives sequential template substitution, escapes a quoting region, and exposes an exec macro to the dispatcher.
Public Python and Nuclei reproducers were reported to work repeatedly against the original 2.4 RC7 binary, and upload permission is unnecessary.
This is a distinct sink from CVE-2024-23692, and no patch is available.
Progressive Robot hMailServer, a Windows SMTP, POP3 and IMAP mail server.
A backslash followed by an apostrophe can close the generated password string and inject JScript before authentication succeeds.
The path requires a known active username and the non-default OnClientValidatePassword JScript hook.
The upstream correction ships in hMailServer 6.3.4.
Netcore NR289-GE, an embedded SMB router and wireless access-point controller.
Placing .ico before a CGI path bypasses both Boa and CGI permission checks, exposing handlers that interpolate form values into root shell commands.
The researcher demonstrated root command execution against extracted firmware under QEMU.
The path is normally limited to LAN management reachability, and no vendor patch has been identified.
Buffalo WEX-G300, a consumer Wi-Fi range extender running embedded firmware.
An attacker with administrator credentials and configuration-interface access can escape a web-form field into an operating-system command.
Buffalo has released fixed firmware.
Buffalo WSR-300HP Wi-Fi routers and WEX-G300 Wi-Fi range extenders running embedded firmware.
Crafted input reaches a stack-based overflow without authentication and puts the management service into a denial-of-service state.
The management interface must be reachable, and internet exposure requires optional remote access.
Buffalo has published fixed versions.
CoreGraphics in supported iPhones and iPads running the iOS 26 branch; Apple also shipped corresponding macOS fixes
CVE-2026-86950 is an out-of-bounds write in CoreGraphics that can execute code when an affected device processes a crafted file.
Apple says it is aware of possible exploitation against specifically targeted individuals.
Apple has not disclosed the file format, delivery channel, victim interaction, processing context, victims, or post-execution privilege.
Apple fixed the flaw in current supported updates.
No new signed-component revocation, bootloader control-flow proof, Secure Boot bypass, TPM key-recovery path, or U-Boot execution proof was established.
Recent Linux and BlueZ activity added assignments, stable-version bookkeeping, tests, and packaging for known flaws without a new Bluetooth primitive.
No recent event widened physical-access capability; the malicious-HID Linux kernel primitive predates this daily window.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.