In its weekend security advisory, Citrix said it fixed two bugs. CVE-2026-88771 and CVE-2026-88772 ... "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.
F5 has fixed a critical zero-day bug in its BIG-IP AccessPolicy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code ... It received a critical 9.3 CVSS v4.0 score - so patch now.
The exploit, dubbed “Plugin4Shell,” is a “first-of-its-kind AI supply-chain attack,” according to threat hunters at Air, a security startup focused on protecting enterprise AI agents ...Microsoft didn’t fix the flaw in Copilot ... ® .
Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling Plugin4Shell, to the vendors concerned, and most of them have now released a patch for it, the researchers wrote in a blog post on Thursday ... .