Severity: HighAction: Review

Siemens Desigo CC family

View CSAF Summary A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client…

Excerpt from the primary source: CISA Cybersecurity Advisories

Who is affected

Critical infrastructure

What you should do · Review

Review whether your organization uses the affected products and assess exposure using the linked advisories.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Siemens Desigo CC family CISA Cybersecurity Advisories · cisa.gov · Sep 22, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns

CISA added CVE-2026-88779 (Citrix NetScaler) to its Known Exploited Vulnerabilities catalog on October 4, 2026, which means there is reliable evidence of exploitation in the wild. Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

Why it matters

CISA lists this as exploited in the wild. Unpatched NetScaler ADC / Gateway systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: HighAction: Patch

Fortra Patches Critical Vulnerabilities in BoKS

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Patch

Apply the vendor's security update for the affected products.

Severity: HighAction: PatchExploitation: Suspected

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Patch

Apply the vendor's security update for the affected products.