Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
blog

FOCUS FRIDAY: TPRM Insights on Critical Vulnerabilities in Kiteworks, Citrix NetScaler, MikroTik RouterOS, OpenSSL, and WordPress Core

Published

Oct 2, 2026

Contributors

Hakan Karabacak

Introduction

This week's Focus Friday covers five FocusTags® spanning enterprise secure content collaboration, network routing infrastructure, foundational cryptography libraries, the world's most widely deployed content management system, and a second Citrix NetScaler advisory within the same reporting cycle. Two tags carry CISA Known Exploited Vulnerabilities listings with confirmed in-the-wild exploitation: Citrix NetScaler's latest advisory discloses two zero-day unauthenticated remote code execution vulnerabilities affecting all default deployments, with 23,000+ exposed instances and a three-day federal patch deadline; and WordPress Core's pre-authentication path traversal chains through PEAR's pearcmd.php to unauthenticated remote code execution across every WordPress installation back to version 4.7.0. Kiteworks issued an unprecedented precautionary shutdown advisory driven by a federal intelligence warning — without a CVE assignment or published technical details — an event where standard vulnerability management signals are entirely absent. MikroTik RouterOS returns with a new integer underflow RCE distinct from the prior MikroTrick cluster, and OpenSSL closes the week with four HIGH severity vulnerabilities affecting DTLS, X.509 certificate handling, and QUIC.

The highest-urgency events this week are Citrix NetScaler's confirmed zero-day unauthenticated RCEs affecting all default deployments — with a three-day federal patch deadline from CISA — and WordPress Core's CISA KEV-listed pre-authentication exploit chain with a public proof-of-concept available. Kiteworks represents a distinct urgency category: an intelligence-driven shutdown event affecting a platform trusted with the most sensitive regulated-industry data, where the absence of a CVE means standard patch verification workflows do not confirm remediation. Three of this week's five tags require active incident-response-class vendor engagement rather than standard patch tracking.

10.2 kiteworks main

Filtered view of vendors with the Kiteworks FocusTag® on the Black Kite platform.

Kiteworks

What is this vulnerability?

Kiteworks is an enterprise secure content collaboration platform used extensively in regulated industries — government, healthcare, defense, and financial services — for secure file sharing, email encryption, and managed file transfer of sensitive and controlled data.

Kiteworks, a U.S.-based technology company formerly known as Accellion, has previously been associated with a major cybersecurity incident involving the Clop ransomware group, which remains active today. In 2021, Clop published data allegedly stolen from numerous organizations through vulnerabilities in Accellion's File Transfer Appliance (FTA). The attacks themselves began in mid-December 2020.

In the latest incident, Kiteworks advised customers worldwide to temporarily shut down their servers for a six-hour period on Saturday after receiving threat intelligence warning of a potential cyberattack. However, the company did not disclose any specific details regarding the nature of the threat intelligence.

The advisory, issued on September 25, 2026 and released publicly on September 26, covered all customer on-premises deployments. It stemmed from a federal intelligence warning about an imminent, specific threat of cyberattack against Kiteworks servers.

During the investigation triggered by the intelligence warning, a vulnerability in the Advanced Forms component was identified. Kiteworks disclosed that fewer than 1% of customers were affected by this Advanced Forms flaw, which has been remediated in Kiteworks version 9.5.1. Kiteworks is working with Mandiant to support its ongoing investigation. Unlike standard vulnerability disclosures, no CVE was assigned and no technical details of the vulnerability mechanism have been made public as of the advisory date. The precautionary shutdown was proactive, not triggered by confirmed exploitation, meaning standard CVE-based vulnerability management workflows do not apply to this event.

Separately, 78 CVEs referencing Kiteworks components have been published. Their direct connection to the intelligence-triggered event that prompted the shutdown advisory has not been confirmed. However, several carry critical CVSS scores and are independently relevant to Kiteworks deployments. The table below presents the critical and high-severity CVEs referenced directly on Kiteworks' security advisory pages (security.kiteworks.com):

CVE

CVSS

Vulnerability Name

Detail

CVE-2026-102115

9.8

Password Reset / Account Takeover

Admin account takeover via password reset flaw

CVE-2026-102149

9.4

Certificate Account Hijack (EPG)

Certificate tied to another user → read encrypted mail, sign in as them

CVE-2026-102147

9.3

Unauthenticated Stored XSS (Core)

Admin-triggered XSS → full admin control

CVE-2026-102106

9.1

SSRF (Email Protection Gateway)

Internal URL / cloud metadata access

CVE-2026-102105

9.1

SSRF (Email Protection Gateway)

Internal URL / cloud metadata access

CVE-2026-102104

9.1

SSRF (Email Protection Gateway)

Internal URL / cloud metadata access

CVE-2026-102103

9.1

SSRF (Email Protection Gateway)

Internal URL / cloud metadata access

CVE-2026-102102

9.1

SSRF (Email Protection Gateway)

Internal URL / cloud metadata access

CVE-2026-102109

Critical

SQL Injection (Secure Data Forms)

SQL injection in Secure Data Forms component

CVE-2026-102101

8.1

Insecure Deserialization (Core)

Deserialization of untrusted data in Kiteworks Core

Note: The 78 CVEs published for Kiteworks components have not been confirmed as directly linked to the zero-day event that triggered the precautionary shutdown advisory. The table above reflects only the CVEs referenced directly on security.kiteworks.com and is presented as independently relevant security context.

Why should TPRM professionals care?

Kiteworks is predominantly deployed in highly regulated environments where it serves as a data-movement gateway for an organization's most sensitive information — government contracts, patient health records, classified file sharing, defense contractor data, and financial data transfer. An advanced threat actor targeting Kiteworks infrastructure is specifically targeting the content layer through which the most sensitive data flows. The precautionary shutdown advisory — an unusual step driven by a federal intelligence warning rather than a confirmed breach — signals a threat severity that exceeds standard vulnerability patch cycles.

The absence of a CVE does not reduce the TPRM risk; it increases it. Vendors affected by this event cannot assess their own exposure through standard vulnerability scanning because there is no CVE to scan for. TPRM teams whose vendors in regulated sectors rely on Kiteworks for sensitive data exchange must treat this as an incident-response-class engagement requiring direct vendor outreach and forensic confirmation — not a patch verification exercise.

What questions should TPRM professionals ask vendors?

  1. Have you applied Kiteworks version 9.5.1 or later, which remediates the Advanced Forms vulnerability identified during the investigation, and for any servers taken offline per the precautionary advisory, have they been inspected for signs of compromise before being brought back online?
  2. Are you working with Kiteworks support to determine whether your installation is among the fewer than 1% affected by the Advanced Forms vulnerability, and what was the conclusion of that assessment?
  3. Have you engaged Mandiant or another qualified incident response firm to conduct a compromise assessment on Kiteworks infrastructure that was internet-accessible prior to the precautionary shutdown?
  4. Have you reviewed Kiteworks access and audit logs for anomalous activity, unauthorized access, data exfiltration indicators, or unexpected administrative actions in the period before the shutdown advisory was issued?
  5. What categories of data were accessible through your Kiteworks deployment — including CUI, PHI, PII, or financial data — and have relevant data owners and regulatory obligations been evaluated in the context of this precautionary shutdown?

Remediation recommendations

  • Upgrade all Kiteworks deployments to version 9.5.1 immediately to remediate the Advanced Forms vulnerability identified during the investigation; do not bring offline servers back online without first completing a compromise assessment.
  • Treat any Kiteworks deployment that was internet-accessible before the precautionary shutdown as potentially compromised until a qualified forensic assessment determines otherwise; the absence of alerts or known breach indicators is not sufficient evidence of no compromise.
  • Engage Kiteworks professional services or Mandiant to assess whether your installation falls within the affected population and to review forensic evidence of any unauthorized access.
  • Review the CVEs published for Kiteworks components at security.kiteworks.com and assess your deployment's exposure to critical and high-severity vulnerabilities independently of the zero-day event, particularly those listed in the table above.
Black Kite's Kiteworks FocusTag details critical insights for TPRM Professionals.

Black Kite's Kiteworks FocusTag® details critical insights on the event for TPRM professionals.

Citrix NetScaler - Sep2026 (Latest)

What is this vulnerability?

Citrix NetScaler ADC and NetScaler Gateway are widely deployed enterprise perimeter appliances providing application delivery, load balancing, SSL/TLS offloading, and secure remote access. The September 2026 Latest advisory covers eight CVEs (CVE-2026-88771 through CVE-2026-88778) across the NetScaler product line. The two most critical flaws are both confirmed actively exploited zero-days. CVE-2026-88771 (CVSSv4 9.5, CVSSv3 9.8) is an improper input validation vulnerability enabling unauthenticated remote code execution on all default NetScaler deployments — no special configuration required, no authentication, no user interaction. CVE-2026-88772 (CVSSv4 9.5, CVSSv3 8.1) is a memory overflow vulnerability triggered via DTLS, also enabling unauthenticated remote code execution. CVE-2026-88773 (CVSSv3 10.0) covers HTTP Request/Response smuggling via inconsistent HTTP request interpretation. CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777 (each CVSS 9.8) are additional memory overflow vulnerabilities. CVE-2026-88774 (CVSS 7.2) and CVE-2026-88778 (CVSS 7.5, predictable value from previous values) cover additional implementation flaws.

Both CVE-2026-88771 and CVE-2026-88772 were zero-days at the time CISA added them to the Known Exploited Vulnerabilities catalog on September 27, 2026, with a federal agency patch deadline of September 30, 2026 — a three-day remediation window that underscores the severity. More than 23,000 internet-exposed NetScaler instances have been identified globally. This is the second critical NetScaler advisory in this reporting cycle, following CVE-2026-19490's authentication bypass from the prior FocusTag®, and continues NetScaler's documented pattern of rapid weaponization after disclosure. The complete fix requires upgrading NetScaler ADC and Gateway to version 14.1-73.37 or 13.1-64.23. Cloud Software Group-managed services are not affected.

Why should TPRM professionals care?

Two independently confirmed zero-day RCE vulnerabilities in a single NetScaler advisory — both requiring no authentication and no special configuration — means that vendors running any version of NetScaler ADC or Gateway prior to 14.1-73.37 must be treated as potentially compromised rather than simply unpatched. The three-day federal patch deadline from CISA confirms the government's assessment of imminent, active exploitation risk. NetScaler's documented history of rapid mass-exploitation — CVE-2019-19781 and CVE-2023-3519 were each weaponized at scale within days — means that delay beyond the initial disclosure window carries compounding compromise risk. TPRM teams must verify not only patch deployment but also whether a compromise assessment has been conducted for the period the appliance ran a vulnerable version while internet-accessible.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded all NetScaler ADC and Gateway deployments to version 14.1-73.37 or 13.1-64.23, and was this completed before the September 30, 2026 CISA-mandated federal deadline?
  2. For any NetScaler appliance that ran a vulnerable version while internet-facing after the September 27, 2026 disclosure, have you conducted a compromise assessment including forensic review of system artifacts, credential rotation, and termination of all active sessions?
  3. Have you reviewed NetScaler and perimeter logs for exploitation indicators of CVE-2026-88771 and CVE-2026-88772, including unexpected inbound DTLS traffic patterns, anomalous process spawning from the appliance, and unauthorized outbound network connections?
  4. What is the complete version inventory of all NetScaler ADC and Gateway appliances in your environment — including those not in the primary network perimeter — and have all been confirmed patched?
  5. Given that this is the second critical NetScaler advisory in this reporting cycle, has your emergency patch SLA for NetScaler been reviewed, and what process changes have been made to ensure sub-24-hour deployment for future zero-day advisories?

Remediation recommendations

  • Upgrade all NetScaler ADC and Gateway deployments to version 14.1-73.37 or 13.1-64.23 immediately on an emergency basis; these are the complete fixes for all eight CVEs in this advisory, and no workarounds exist for the zero-day RCEs.
  • Conduct compromise assessments for all NetScaler appliances that were internet-accessible in a vulnerable configuration between disclosure and patching; treat confirmed zero-day active exploitation as a presumed-compromise scenario pending forensic review.
  • Rotate all credentials for accounts and services authenticated through the NetScaler gateway, terminate all active sessions, and review all access granted through the perimeter appliance during the vulnerable window.
  • Restrict NetScaler management interfaces to trusted internal IP ranges and review DTLS configuration — disabling DTLS on any interface where it is not operationally required reduces exposure to CVE-2026-88772's memory overflow attack vector.
Black Kite's Citrix NetScaler FocusTag details critical insights for TPRM professionals

Black Kite's Citrix NetScaler - Sep2026 (Latest) FocusTag® details critical insights on the event for TPRM professionals.

MikroTik RouterOS - Sep2026

What is this vulnerability?

MikroTik RouterOS is one of the most widely deployed network operating systems for small office, enterprise edge, and ISP routing infrastructure globally, with hundreds of thousands of internet-facing devices. On September 29, 2026, CISA published ICS Advisory ICSA-26-272-06 covering CVE-2026-84411, an integer underflow vulnerability in MikroTik RouterOS. The integer underflow occurs in a core routing protocol parsing component and can be triggered remotely by an unauthenticated attacker, causing either a buffer overflow leading to arbitrary code execution or a service crash resulting in denial of service — depending on memory layout at exploitation time. The complete fix is RouterOS 7.24, covering affected versions across multiple release trains.

Two additional CVEs are also associated with this FocusTag®. CVE-2026-86060 (CVSS 9.8) is an argument-handling flaw in the SSH login path: usernames beginning with a prohibited character circumvent the trusted-host restriction, enabling unauthorized authentication. CVE-2026-67276 (CVSS 8.1) is an SSH key comparison bypass: RouterOS does not compare the complete RSA public key when matching SSH authentication requests to authorized user keys — checking only key type and partial content — allowing an attacker with a partially matching key to authenticate as a trusted user. All three vulnerabilities in this FocusTag® are distinct from the MikroTrick vulnerability cluster (CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281) tracked in the September 11, 2026 FocusTag®. The CISA advisory covers critical infrastructure and operational technology contexts where MikroTik devices are deployed.

Why should TPRM professionals care?

MikroTik RouterOS is frequently overlooked in TPRM assessments because it appears at the network infrastructure layer rather than in application inventories. Yet RouterOS devices sit at the perimeter of many organizations' networks — including vendors and third-party suppliers in critical infrastructure, manufacturing, ISP, and SMB sectors. An unauthenticated RCE at the routing layer provides immediate network-level access: the ability to inspect, redirect, or drop all traffic flowing through the device, tunnel into internal network segments, and pivot to any system reachable through the affected router. The SSH key comparison bypass (CVE-2026-67276) and SSH username argument flaw (CVE-2026-86060) are separately exploitable without triggering the integer underflow, meaning all three vulnerabilities are independently relevant attack vectors. TPRM teams assessing vendors in industrial, critical infrastructure, healthcare network, and SMB contexts where MikroTik is prevalent should verify RouterOS version currency across the full device inventory.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded all MikroTik RouterOS devices to version 7.24 to remediate CVE-2026-84411 (integer underflow RCE), CVE-2026-67276 (SSH key comparison bypass), and CVE-2026-86060 (SSH username argument flaw)?
  2. Do you maintain a complete inventory of MikroTik RouterOS devices in your environment, including branch locations, out-of-band management networks, and devices managed by third-party network service providers that may not be tracked in standard IT asset inventories?
  3. Have you reviewed RouterOS device logs for exploitation indicators of CVE-2026-84411 and CVE-2026-86060, including unexpected SSH authentication events, anomalous process activity, or unusual outbound traffic patterns from routing infrastructure?
  4. For devices that cannot be immediately upgraded, have you restricted SSH, Winbox, and other management interfaces to trusted internal IP ranges only, and isolated internet-accessible devices from sensitive internal network segments?
  5. Were any MikroTik devices in your environment previously affected by the MikroTrick vulnerability cluster (CVE-2026-67276, CVE-2026-86060, CVE-2026-67277 through CVE-2026-67281) from the September 11 FocusTag®, and if so, have those systems been fully remediated and assessed for residual compromise?

Remediation recommendations

  • Upgrade all MikroTik RouterOS devices to version 7.24 immediately to remediate all three CVEs in this FocusTag®; earlier RouterOS release trains require corresponding backport updates per MikroTik's release notes.
  • Restrict SSH, Winbox, and web management interfaces on MikroTik devices to trusted management IP ranges; disable interfaces on internet-accessible WAN interfaces where management access is not operationally required.
  • Treat any MikroTik RouterOS device with internet-accessible SSH that ran a vulnerable version as potentially compromised and conduct forensic review of system state, authentication logs, and traffic data.
Black Kite's MikroTik RouterOS FocusTag details critical insights for TPRM professionals

Black Kite's MikroTik RouterOS - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

OpenSSL - Sep2026

What is this vulnerability?

OpenSSL is the foundational TLS/SSL cryptography library underlying the majority of internet-facing encrypted communications infrastructure, including web servers, email systems, VPN gateways, and network devices. On September 29, 2026, the OpenSSL Security Advisory disclosed four HIGH severity vulnerabilities across multiple OpenSSL components. CVE-2026-84782 (CVSS 8.2) is an out-of-bounds read in DTLS retransmission logic: when a handshake message write is suspended mid-stream, the retransmission path reads beyond the allocated buffer boundary, potentially causing crashes or information leakage during DTLS handshakes. CVE-2026-84783 (CVSS 7.5) is a use-after-free in X.509 certificate extension caching: when the same certificate is used concurrently by multiple threads for the first time, cached extension data may be freed while another thread is still reading it — this vulnerability affects OpenSSL 4.0 only. CVE-2026-72897 (CVSS 7.5) is an out-of-bounds write in SSL_CTX mid-handshake switching: a TLS server that calls SSL_set_SSL_CTX() to switch to a different SSL_CTX during an active handshake may write to freed memory. CVE-2026-84784 (CVSS 7.5) is a QUIC resource exhaustion: a remote peer can circumvent the connection ID frame count limit, flooding the local QUIC stack with NEW_CONNECTION_ID frames and exhausting available memory.

None of the four vulnerabilities carry CISA KEV listings or have confirmed active exploitation as of the advisory date. Approximately 1.8 million internet-facing instances of OpenSSL-dependent services have been identified globally. Affected OpenSSL branches are 3.0, 3.1, 3.2, 3.3, and 3.4 (all four CVEs), plus 4.0 additionally for CVE-2026-84783. Fixed versions are 3.0.16, 3.1.8, 3.2.5, 3.3.4, 3.4.1, and 4.0.1 respectively.

Why should TPRM professionals care?

OpenSSL underlies nearly every encrypted channel across internet infrastructure — from web servers and email to VPN gateways and network appliances. While none of the September 2026 vulnerabilities carry KEV listings, HIGH severity flaws in DTLS, X.509 certificate handling, and QUIC are protocol-level issues relevant to any organization exchanging encrypted communications with vendors whose TLS stacks have not been updated. CVE-2026-84782's DTLS exposure is particularly relevant for organizations using DTLS-based protocols including VoIP (DTLS-SRTP), WebRTC, and DTLS-based VPNs. CVE-2026-84784's QUIC exhaustion is relevant to vendors operating modern HTTP/3 infrastructure. The 1.8 million exposed instances make this a broad-footprint advisory requiring systematic portfolio assessment rather than targeted vendor engagement.

What questions should TPRM professionals ask vendors?

  1. Have you updated OpenSSL to version 3.4.1, 3.3.4, 3.2.5, 3.1.8, or 3.0.16 (per your deployed branch) across all directly managed installations, including those embedded in network appliances or third-party products where updates require vendor firmware releases?
  2. Do any of your internet-facing services use DTLS for encrypted communications — including VoIP (DTLS-SRTP), WebRTC, or DTLS-based VPNs — and have these been assessed for CVE-2026-84782 exposure and patched?
  3. Are any of your services running OpenSSL 4.0, which is additionally affected by CVE-2026-84783 (use-after-free in X.509 certificate extension caching under concurrent thread use), and if so, have these been updated to OpenSSL 4.0.1?
  4. Do you operate QUIC/HTTP/3 infrastructure using OpenSSL's QUIC implementation, and have these services been patched for CVE-2026-84784's connection ID frame exhaustion vulnerability?
  5. What is your process for tracking OpenSSL advisory releases and deploying patches across both directly managed OpenSSL installations and third-party products that bundle OpenSSL, and how is patch deployment across bundled instances verified?

Remediation recommendations

  • Update OpenSSL to the fixed version for each deployed branch: 3.0.16, 3.1.8, 3.2.5, 3.3.4, or 3.4.1 for the September 29 advisory; 4.0.1 for CVE-2026-84783 (OpenSSL 4.0 only).
  • Monitor vendor firmware update releases for network devices, security appliances, and embedded products that bundle OpenSSL; direct OpenSSL package updates do not address library versions embedded in third-party firmware.
  • Prioritize DTLS-dependent service patching for CVE-2026-84782 and QUIC/HTTP/3 service patching for CVE-2026-84784, as these are protocol-specific and require targeted service identification before patch verification.
Black Kite's OpenSSL FocusTag details critical insights on the event for TPRM professionals.

Black Kite's OpenSSL - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

WordPress Core - Sep2026

What is this vulnerability?

WordPress is the world's most widely deployed content management system, powering approximately 43% of all websites globally. CVE-2026-87902 (CVSSv4 9.2, EPSS 2.88%) is a pre-authentication path traversal vulnerability in WordPress Core's page template resolution function in wp-includes/template.php. The vulnerability has been present in every WordPress release since version 4.7.0, affecting all users across the entire install base for nearly a decade. The exploit chain proceeds as follows: an unauthenticated attacker sends a crafted request controlling the page_template parameter or similar path-controllable template resolution input; WordPress's get_page_template() resolves the attacker-controlled path without adequate traversal validation, allowing the filename to reference any readable .php file outside the active theme directory; by targeting PEAR's pearcmd.php — present by default on many PHP server configurations — an attacker can execute arbitrary PHP commands server-side. The result is full unauthenticated remote code execution with no authentication, no user interaction, and no special precondition beyond PEAR's presence on the server.

CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog on September 25, 2026. A public proof-of-concept exploit is available on GitHub. The EPSS of 2.88% places this CVE in the top 3% of all tracked CVEs by exploitation probability. The vulnerability is exploitable across all WordPress versions from 4.7.0 through 7.1.1. WordPress patches are available in version 7.1.2 with backports for all supported release branches down to WordPress 4.7.37.

Why should TPRM professionals care?

WordPress's ubiquity creates a uniquely large TPRM exposure surface: with approximately 43% of all websites running WordPress, a significant fraction of any vendor's internet-facing web presence is potentially affected. Pre-authentication RCE means attackers require no user interaction, no credentials, and no existing access before achieving code execution — making this vulnerability suitable for automated scanning and mass exploitation at internet scale. The combination of CISA KEV listing, a public PoC, and an EPSS of 2.88% creates a high-velocity exploitation threat that is likely already being actively exploited by the time TPRM outreach begins. TPRM teams should query vendor portfolios for vendors with internet-facing WordPress installations at versions prior to 7.1.2 and initiate structured vendor engagement immediately.

What questions should TPRM professionals ask vendors?

  1. Have you updated all WordPress Core installations to version 7.1.2 or the appropriate backport for older branches (minimum 4.7.37 for WordPress 4.7.x) across all internet-accessible WordPress sites?
  2. Do you maintain a complete inventory of all WordPress installations across your web properties — including sites managed by third parties such as web agencies, hosting providers, or decentralized internal teams — and has this inventory been used to verify comprehensive patch deployment for CVE-2026-87902?
  3. Have you reviewed WordPress access logs for exploitation indicators of CVE-2026-87902, including requests containing path traversal patterns in template-resolution parameters, references to pearcmd.php, or unexpected PHP execution evidence in server error logs?
  4. Have you disabled or removed PEAR from WordPress hosting environments where it is not required, as a defense-in-depth measure to eliminate the file-inclusion-to-code-execution chain's final execution step even on unpatched WordPress versions?
  5. Given that this vulnerability has been present since WordPress 4.7.0 and was added to CISA KEV on September 25, 2026, was an emergency patch deployment completed outside normal update cycle windows, and what is your WordPress Core patch SLA for CISA KEV-listed vulnerabilities?

Remediation recommendations

  • Update all WordPress Core installations to version 7.1.2 or the applicable backport release (minimum 4.7.37 for WordPress 4.7.x) immediately; all WordPress release branches back to 4.7 have received patches.
  • Remove PEAR from WordPress hosting environments where it is not operationally required; pearcmd.php is the execution endpoint of the CVE-2026-87902 exploit chain, and its removal eliminates the code execution step even on unpatched WordPress installations.
  • Implement Web Application Firewall rules blocking path traversal patterns — including ../, ..\ sequences, null bytes, and URL-encoded variants — in page_template and similar template resolution parameters as a defense-in-depth measure for sites that cannot be immediately updated.
  • Treat any WordPress installation that ran a vulnerable version while internet-accessible after the CISA KEV listing on September 25 as a potential compromise candidate; conduct access log review for exploitation indicators before returning the site to normal operations.
Black Kite's WordPress Core FocusTag details critical insights for TPRM Professionals

Black Kite's WordPress Core - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

How TPRM Professionals Can Leverage Black Kite for These Vulnerabilities

This week's five FocusTags® present an unusually diverse challenge for TPRM professionals: a CVE-less intelligence-driven shutdown event, two confirmed zero-day RCEs on perimeter appliances, a network routing layer vulnerability, a foundational cryptography library advisory, and a decade-old pre-authentication RCE now added to CISA's KEV catalog. Black Kite's platform addresses each of these with distinct capabilities.

For Kiteworks, Black Kite's FocusTag® identifies vendors in your portfolio that rely on Kiteworks infrastructure using internet-observable signals — without requiring a CVE to trigger detection. This is critical for an event where no CVE exists and vendors cannot self-assess through standard scanning. For Citrix NetScaler, Black Kite tracks both this advisory and the prior authentication bypass FocusTag® separately, allowing TPRM teams to identify vendors exposed to both events simultaneously — providing a complete picture of NetScaler risk across this reporting cycle. For WordPress Core, with 43% of all websites potentially affected, Black Kite's version-aware detection enables prioritization within a massive vendor population rather than blanket outreach.

For MikroTik RouterOS, Black Kite surfaces network-layer infrastructure exposures that standard TPRM processes — which typically focus on application-layer inventories — often miss entirely. For OpenSSL, with 1.8 million exposed instances spread across web servers, email systems, appliances, and firmware, Black Kite's portfolio-level identification allows TPRM teams to prioritize patch tracking for vendors with the highest concentration of OpenSSL-dependent internet-facing services. The Bridge connector enables automated questionnaire dispatch to all five FocusTag® vendor populations simultaneously, managing five parallel engagement workstreams as a single coordinated workflow.

Strengthening TPRM Outcomes with Black Kite's FocusTags®

This week's five-tag release illustrates how Black Kite's FocusTags® address threat intelligence scenarios that range from intelligence-driven shutdown events with no CVE to mass-scale pre-authentication RCE on the world's most widely deployed CMS.

  • CVE-Less Event Detection: Kiteworks issued its shutdown advisory without a CVE, meaning standard vulnerability management workflows — CVE scanning, NVD feeds, patch management tools — produce no signal. Black Kite's FocusTag® for Kiteworks identifies affected vendor populations through internet-observable technology presence signals, enabling TPRM engagement for events that are invisible to CVE-based monitoring.
  • Dual-Advisory Perimeter Coverage: Citrix NetScaler received two critical advisories within the same reporting cycle — the prior authentication bypass and this week's zero-day RCE cluster. Black Kite tracks both FocusTags® independently, enabling TPRM teams to identify vendors exposed to both events and prioritize those with compounded perimeter risk across multiple unpatched NetScaler vulnerabilities.
  • Network Infrastructure Layer Visibility: MikroTik RouterOS vulnerabilities sit at the routing layer — outside standard application-layer TPRM assessment scope. FocusTags® surface network-layer exposures that traditional TPRM processes miss, identifying vendors whose internet-facing routing infrastructure runs vulnerable RouterOS versions.
  • Foundational Library Patch Currency Tracking: OpenSSL is present in nearly every internet-facing system, often embedded in third-party firmware and appliances beyond direct patch management control. FocusTags® enable TPRM teams to identify vendors with the highest concentration of OpenSSL-dependent internet-facing services and track library-level patch currency across a 1.8-million-instance global exposure surface.
  • Mass-Scale Pre-Authentication Exploit Prioritization: WordPress Core's CVE-2026-87902 affects 43% of all websites with a public PoC and CISA KEV listing — meaning automated mass exploitation is already in progress at FocusTag® activation time. FocusTags® enable TPRM teams to immediately identify which vendors in their portfolio run internet-facing WordPress at vulnerable versions, focusing engagement resources on confirmed-exposed vendors within the massive WordPress install base.
  • Regulated-Industry Sensitive Data Risk: Kiteworks is concentrated in regulated sectors — government, healthcare, defense, financial services — where a compromise carries regulatory, legal, and national security implications beyond standard breach response. FocusTags® enable TPRM teams to identify vendors in these sectors that rely on Kiteworks, supporting data-sensitivity-weighted risk prioritization.
  • The Bridge: Scalable Multi-Tag Vendor Engagement: With five simultaneous FocusTag® activations spanning divergent technology categories, The Bridge connector enables automated questionnaire dispatch to all five affected vendor populations at once — converting five parallel engagement workstreams into a single managed workflow and ensuring no affected vendor is missed across even a large and diverse third-party portfolio.

FocusTags® in the Last 30 Days

  • Kiteworks: No CVE, Precautionary Shutdown Advisory Driven by Federal Intelligence Warning of Imminent Cyberattack, Advanced Forms Vulnerability Identified.
  • Citrix NetScaler - Sep2026 (Latest): CVE-2026-88771, CVE-2026-88772, and 6 additional CVEs, Two Confirmed Zero-Day Unauthenticated RCEs in All Default NetScaler Deployments and HTTP Smuggling.
  • MikroTik RouterOS - Sep2026: CVE-2026-84411, CVE-2026-86060, CVE-2026-67276, Integer Underflow Enabling Unauthenticated RCE or DoS, SSH Username Argument Flaw Enabling Trusted-Host Bypass, and SSH Key Comparison Bypass in MikroTik RouterOS.
  • OpenSSL - Sep2026: CVE-2026-84782, CVE-2026-84783, CVE-2026-72897, CVE-2026-84784, Out-of-Bounds Read in DTLS Retransmission, Use-After-Free in X.509 Certificate Caching (OpenSSL 4.0), OOB Write in SSL_CTX Switching, and QUIC Resource Exhaustion.
  • WordPress Core - Sep2026: CVE-2026-87902, Pre-Authentication Path Traversal in wp-includes/template.php Enabling Local File Inclusion and Unauthenticated RCE via PEAR pearcmd.php, Present Since WordPress 4.7.0.
  • ScreenConnect - Sep2026: CVE-2026-84869, Missing Authorization Vulnerability in ConnectWise ScreenConnect Client File-Transfer Handling Enabling Worm-Like Malware Propagation to Every Connected Host Session.
  • Exim Mail - Sep2026: CVE-2026-94054, CVE-2026-94056, Out-of-Bounds Write and Use of Uninitialized Resource in Exim PROXY Protocol v1 and v2 Handling Enabling Heap Corruption and Stack Memory Disclosure.
  • Citrix NetScaler - Sep2026: CVE-2026-19490, CVE-2026-19489, Critical Authentication Bypass via Unsigned SAML Assertion Acceptance in NetScaler ADC and Gateway and Memory Overflow via SIP ALG.
  • Apache Tomcat - Sep2026: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, and 5 additional CVEs, WebSocket Security Constraint Bypass, CLIENT_CERT Authentication Failure, and HTTP Request Smuggling in Apache Tomcat 9, 10, and 11.
  • Langflow - Sep2026: CVE-2026-12944, CVE-2026-7524, CVE-2026-0770, CVE-2026-9198, Fourth Critical Vulnerability in Langflow OSS This Reporting Cycle — SSRF via Incomplete DANGEROUS_IMPORTS Blocklist Enabling AWS Credential Theft with False 'Validated: True' Signal.
  • N-central - Sep2026: CVE-2026-86218, CVE-2026-86206, CVE-2026-86207, CVE-2026-18556, CVE-2026-18577, Pre-Authenticated CVSS 10.0 Remote Code Execution Zero-Day and Dual Authentication Bypass Vulnerabilities in N-able N-central RMM Platform.
  • Adobe Commerce & Magento: CVE-2026-75650, CVE-2026-7565, Unauthenticated Template Injection Remote Code Execution in Adobe Commerce and Magento Open Source Affecting All Versions.
  • MikroTrick: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, CVE-2026-67281, CVE-2026-67279, CVE-2026-67278, Six-Vulnerability Set Enabling Unauthenticated RouterOS Takeover via SSH Auth Bypass and Privilege Escalation Chain in MikroTik RouterOS.
  • Fortinet - Sep2026 [Suspected]: CVE-2026-84393, CVE-2026-84391, CVE-2026-22575, Improper Certificate Validation in Agentless ZTNA Portal and Authenticated Denial of Service and Workflow Bypass in FortiOS, FortiProxy, FortiAnalyzer, and FortiManager.
  • MSSQL - Sep2026: CVE-2026-47297, CVE-2026-65669, CVE-2026-67378, CVE-2026-67379, CVE-2026-67636, and 56 additional CVEs, Largest Single-Month SQL Server Disclosure Batch with Unauthenticated RCE and Scope-Breaking Critical Vulnerabilities.
  • SharePoint - Sep2026: CVE-2026-69464, CVE-2026-69716, CVE-2026-69268, and 13 additional CVEs, Six Independent Remote Code Execution Pathways via Low-Privilege Authentication in Microsoft SharePoint Server Subscription Edition.
  • Exchange Server - Sep2026: CVE-2026-69356, CVE-2026-69641, CVE-2026-69355, CVE-2026-55007, and 5 additional CVEs, Unauthenticated XSS Spoofing and Multiple RCE Vulnerabilities in Microsoft Exchange Server.
  • MongoDB - Sep2026: CVE-2026-82067, CVE-2026-82075, CVE-2026-82064, and 18 additional CVEs, Silent Authorization Bypass and Unauthenticated Denial of Service Vulnerabilities in MongoDB Server 7.0, 8.0, and 8.3.
  • Roundcube - Sep2026: No CVE (12 fixes), Zero-Click Stored XSS in TNEF Attachment Handling, SSRF Bypass in CSS Proxy, Email Header Injection, and Cross-User Address Book Access in Roundcube Webmail.
  • Jenkins - Sep2026: CVE-2026-84645, CVE-2026-84647, CVE-2026-84649, CVE-2026-84652, CVE-2026-53435, CVE-2026-70426, Authenticated Remote Code Execution via Deserialization Chain and Multiple Privilege Escalation Paths in Jenkins CI/CD Controller.
  • PaperCut MF/NG - Aug2026: CVE-2026-81578, CVE-2026-82078, Unauthenticated Authentication Bypass via Apache Tapestry Dual-Page Request Format Enabling Unsafe Class Loading Remote Code Execution in PaperCut MF and NG.
  • SonicWall SMA1000 - Aug2026: CVE-2026-83548, CVE-2026-83549, Pre-Authentication SSRF and OS Command Injection Zero-Day Chain Enabling Unauthenticated Remote Code Execution on SonicWall SMA1000 Secure Access Gateways.
  • Sangoma Switchvox: CVE-2026-9586, Unauthenticated SQL Injection via /pa Endpoint Enabling PostgreSQL Superuser OS Command Execution in Sangoma Switchvox SMB Edition.
  • MongoDB BI Connector: CVE-2026-75159, CVE-2026-75573, Kerberos-Triggered Denial of Service and TLS Private-Key Password Disclosure in MongoDB Connector for BI (mongosqld).
  • TrueConf - Aug2026: CVE-2026-72529, CVE-2026-72530, Unauthenticated Pre-Authentication Remote Code Execution via Chained Missing Authentication and Sandbox Escape Vulnerabilities in TrueConf Server, Actively Exploited by Head Mare APT.
  • OpenSSL - Aug2026: CVE-2026-18798, CVE-2026-63072, CVE-2026-63076, and 6 additional CVEs, Denial-of-Service and AEAD Authentication Tag Bypass Vulnerabilities in QUIC, CMS, CMP, DTLS, RPK, and AEAD Components of OpenSSL.
  • Apache Tomcat - Aug2026 (Latest): CVE-2026-65182, CVE-2026-68525, CVE-2026-68569, CVE-2026-65637, and 7 additional CVEs, Multiple Authentication and Authorization Bypass Vulnerabilities in Apache Tomcat Affecting 187,461 Exposed Internet-Facing Services.
  • PostgreSQL - Aug2026: CVE-2026-14669, Heap-Based Buffer Overflow in to_char (timestamptz) Enabling Authenticated Remote Code Execution as OS User in PostgreSQL.
  • WordPress Elementor - Aug2026: CVE-2026-32475, Unauthenticated Arbitrary File Upload to Remote Code Execution via Loop Desynchronization in Elementor Pro WordPress Plugin.
  • Citrix NetScaler - Aug2026: CVE-2026-8452, Pre-Authentication Memory Overflow in SAML Signature Canonicalization enabling Remote Code Execution as Root in NetScaler ADC and NetScaler Gateway.

References

https://techcrunch.com/2026/09/25/kiteworks-urges-customers-to-shut-down-their-servers-amid-imminent-threat-of-cyberattack/

https://thehackernews.com/2026/09/kiteworks-urges-customers-to-shut-down.html

https://www.securityweek.com/kiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability/

https://www.kiteworks.com/company/press-releases/kiteworks-precautionary-shutdown-advisory/

https://security.kiteworks.com

https://www.cve.org/CVERecord?id=CVE-2026-88771

https://www.cve.org/CVERecord?id=CVE-2026-88772

https://www.cve.org/CVERecord?id=CVE-2026-88773

https://www.cve.org/CVERecord?id=CVE-2026-88774

https://www.cve.org/CVERecord?id=CVE-2026-88775

https://www.cve.org/CVERecord?id=CVE-2026-88776

https://www.cve.org/CVERecord?id=CVE-2026-88777

https://www.cve.org/CVERecord?id=CVE-2026-88778

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096

https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway

https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/

https://www.cve.org/CVERecord?id=CVE-2026-84411

https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06

https://openssl-library.org/news/secadv/20260929.txt

https://openssl-library.org/news/vulnerabilities/

https://nvd.nist.gov/vuln/detail/CVE-2026-84782

https://nvd.nist.gov/vuln/detail/CVE-2026-84783

https://nvd.nist.gov/vuln/detail/CVE-2026-72897

https://nvd.nist.gov/vuln/detail/CVE-2026-84784

https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/

https://thecyberexpress.com/openssl-dtls-flaw-cve-2026-84782/

https://www.cve.org/CVERecord?id=CVE-2026-87902

https://github.com/advisories/GHSA-7hp8-65ch-5whp

https://wordpress.org/news/2026/09/wordpress-7-1-2/

https://github.com/ressl/cve-2026-87902-poc

https://equixly.com/blog/2026/09/24/cve-2026-87902-from-wordpress-path-traversal-to-rce-via-pear/