2 Oct 2026
Week in review
Greetings,
October is Cyber Security Awareness Month, and the Australian Cyber Security Centre (ACSC) is encouraging all Australians and organisations to take action to strengthen their cyber security posture. This year's theme, “Building our cyber safe culture", focuses on three simple but effective steps: keeping software up to date, using strong and unique passphrases, and enabling multi-factor authentication (MFA) on all accounts.
For cyber security professionals and organisational leaders, the ACSC will spotlight four key focus areas throughout October: event logging, legacy technology, supply chain and third-party risk, and quantum readiness. These topics aim to help organisations improve resilience and better protect critical systems and data.
As Cyber Security Awareness Month gets underway, now is a great opportunity to review your organisation's cyber security practices and ensure the fundamentals are in place to reduce cyber risk.
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Date: 2026-09-27
Author: Bleeping Computer
[See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.11691/]
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Date: 2026-09-30
Author: The Hacker News
[AUSCERT has informed the affected members via Critical MSINs]
[Please see AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.11917/]
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.
The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a CVSS score of 9.8 out of 10. It sits in the part of the Manager's API that handles login sessions.
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Date: 2026-09-28
Author: The Hacker News
[AUSCERT has published security bulletins for these Apple updates:
https://portal.auscert.org.au/bulletins/ESB-2026.11802/
https://portal.auscert.org.au/bulletins/ESB-2026.11801/]
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.
The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.
The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue.
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Date: 2026-10-01
Author: The Record
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group (GTIG) said Wednesday.
Total vulnerability disclosures began the year at 5,045 in January and had jumped to more than 10,000 for July and August.
“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” the researchers said.
Queensland government department loses $800,000 in cyber attack – ABC News
Date: 2026-09-30
Author: ABC News
The Customer Services, Open Data, and Small and Family Business department lost $809,000 in public money due to an external cyber attack for financial gain.
The department plays a lead role in strengthening the state government’s cyber security capabilities.
No government data or sensitive information was compromised during the incident.
ESB-2026.11795 – Apache Tomcat: CVSS (Max): 9.8
Apache Tomcat contains a vulnerability that could allow attackers to bypass security constraints protecting WebSocket endpoints.
ESB-2026.11802 – Apple macOS Sequoia: CVSS (Max): 8.8
Apple macOS contains a CoreGraphics vulnerability that could allow arbitrary code execution via a malicious file.
ESB-2026.11827 – MikroTik RouterOS: CVSS (Max): 9.8
MikroTik have provided update versions for the RouterOS. Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.
ESB-2026.11900 – GitLab Community Edition (CE) and Enterprise Edition (EE): CVSS (Max): 10.0
Updated versions for GitLab Community Edition (CE) and Enterprise Edition (EE) were released on September 23, 2026. Gitlab strongly recommends that all self-managed GitLab installations be upgraded to one of these versions immediately.
ESB-2026.11917 – Cisco Catalyst SD-WAN Manager: CVSS (Max): 9.8
Cisco has released software updates that address a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
Stay safe, stay patched and have a good weekend!
The AUSCERT team