Severity: CriticalAction: Act nowExploitation: Exploited

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.

Excerpt from the primary source: SecurityWeek

Who is affected

Security professionals

Why it matters

Source reporting says attackers are already exploiting this, so exposed affected systems are at immediate risk.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Act now

Treat this as an emergency. Identify every system running the affected products, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild SecurityWeek · securityweek.com · Oct 9, 2026 · Primary source
Severity: HighAction: Patch

Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

Patch

Apply the vendor's security update for NetScaler ADC / Gateway.

Severity: ElevatedAction: Be aware

International coalition seizes tools used by cyber firm behind Flax Typhoon

The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.