Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution – PATCH: NOW

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. NetScaler ADC is a networking product that functions as an Application Delivery Controller (ADC), optimizing, securing, and ensuring reliable availability of applications for businesses. NetScaler Gateway is a secure remote access solution that provides users with single sign-on (SSO) access to applications and resources from any device. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.

THREAT INTELLIGENCE:
There are reports of CVE-2026-88771 and CVE-2026-88772 being actively exploited in the wild.

SYSTEMS AFFECTED:

  • NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 versions prior to 13.1-64.23
  • NetScaler ADC FIPS versions prior to 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.279 FIPS and NDcPP

RISK:

Government:
Large and medium government entities: HIGH
Small government entities: MEDIUM

Businesses:
Large and medium business entities: HIGH
Small business entities: MEDIUM

Home Users: N/A

TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. Details of the vulnerabilities are as follows:

Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):

  • A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. All NetScaler ADC and NetScaler Gateway deployments are affected by default, with no additional feature required. (CVE-2026-88771)
  • A memory overflow vulnerability leading to remote code execution or denial of service, affecting deployments with DTLS configuration enabled (enabled by default on VPN virtual servers). (CVE-2026-88772)
  • An HTTP request smuggling vulnerability affecting deployments with HTTP configuration enabled. (CVE-2026-88773)
  • A feature policy bypass resulting from improper handling of HTTP URL-based policy expressions. (CVE-2026-88774)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. (CVE-2026-88775)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting Load Balancing virtual servers of type Oracle. (CVE-2026-88776)
  • A memory overflow vulnerability leading to unpredictable or erroneous behavior or denial of service, affecting LB/CS or CGNAT-LSN/NAT64 deployments with a non-HTTP Layer 7 protocol feature enabled. (CVE-2026-88777)
  • A TCP Initial Sequence Number (ISN) prediction vulnerability affecting deployments with TCP configuration enabled. (CVE-2026-88778)
  • Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.

RECOMMENDATIONS:
We recommend the following actions be taken:

  • Apply appropriate updates provided by Citrix to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.5: Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
    • Safeguard 12.1: Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
       
  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
    • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
    • Safeguard 5.5: Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
       
  • Vulnerability scanning is used to find potentially exploitable software vulnerabilities to remediate them. (M1016: Vulnerability Scanning)
    • Safeguard 16.13: Conduct Application Penetration Testing: Conduct application penetration testing. For critical applications, authenticated penetration testing is better suited to finding business logic vulnerabilities than code scanning and automated security testing. Penetration testing relies on the skill of the tester to manually manipulate an application as an authenticated and unauthenticated user.
       
  • Architect sections of the network to isolate critical systems, functions, or resources. Use physical and logical segmentation to prevent access to potentially sensitive systems and information. Use a DMZ to contain any internet-facing services that should not be exposed from the internal network. (M1030: Network Segmentation)
    • Safeguard 12.2: Establish and Maintain a Secure Network Architecture: Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.
       
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.


REFERENCES:CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88771
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88772
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88773
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88774
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88775
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88776
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88777
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-88778

Citrix:
https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html

A Vulnerability in Apple Products Could Allow for Arbitrary Code Execution – PATCH: NOW

A vulnerability has been discovered in Apple products that could allow for arbitrary code execution.

  • macOS Sequoia (macOS 15) is an operating system version for Mac computers released by Apple in late 2024.
  • macOS Tahoe (macOS 26) is an operating system version for Mac computers released by Apple in late 2025.
  • iOS is Apple’s mobile operating system.
  • IPadOS is Apple’s mobile operating system exclusively for its iPad line of tablet computers.

Successful exploitation of the vulnerability could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

THREAT INTELLIGENCE:
Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. 

SYSTEMS AFFECTED:

  • Versions prior to iOS 26.7.1 and iPadOS 26.7.1
  • Versions prior to macOS Tahoe 26.7.1
  • Versions prior to macOS Sequoia 15.8.1

RISK:
Government:

  • Large and medium government entities: High
  • Small government: Medium

Businesses:

  • Large and medium business entities: High
  • Small business entities: Medium

Home Users: Low

TECHNICAL SUMMARY:
A vulnerability has been discovered in Apple products that could allow for arbitrary code execution. Details of the vulnerability are below:  

Tactic: Initial Access (TA0001): 
Technique: Drive-by Compromise (T1189):

  • Processing a maliciously crafted file may lead to arbitrary code execution. (CVE-2026-86950)

Successful exploitation of the vulnerability could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

RECOMMENDATIONS:
We recommend the following actions be taken:

  • Apply appropriate updates provided by Apple to vulnerable systems immediately after appropriate testing. (M1051:Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
    • Safeguard 9.1: Ensure Use of Only Fully Supported Browsers and Email Clients: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026:Privileged Account Management)
    • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
    • Safeguard 5.4: Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050:Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Restrict use of certain websites, block downloads/attachments, block JavaScript, restrict browser extensions, etc. (M1021:Restrict Web-Based Content)
    • Safeguard 9.2: Use DNS Filtering Services: Use DNS filtering services on all enterprise assets to block access to known malicious domains.
    • Safeguard 9.3: Maintain and Enforce Network-Based URL Filters: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
    • Safeguard 9.6: Block Unnecessary File Types: Block unnecessary file types attempting to enter the enterprise’s email gateway.
  • Block execution of code on a system through application control, and/or script blocking. (M1038:Execution Prevention)
    • Safeguard 2.5: Allowlist Authorized Software: Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
    • Safeguard 2.6: Allowlist Authorized Libraries: Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, .so, etc., files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.
    • Safeguard 2.7: Allowlist Authorized Scripts: Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
  • Use capabilities to prevent suspicious behavior patterns from occurring on endpoint systems. This could include suspicious process, file, API call, etc. behavior. (M1040:Behavior Prevention on Endpoint)
    • Safeguard 13.2: Deploy a Host-Based Intrusion Detection Solution: Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
    • Safeguard 13.7: Deploy a Host-Based Intrusion Prevention Solution: Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017:User Training)
    • Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.

REFERENCES:

CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86950

Apple:
https://support.apple.com/en-us/100100
https://support.apple.com/en-us/149226
https://support.apple.com/en-us/149228
https://support.apple.com/en-us/149229

NIST NEW BLOG | Stronger Cybersecurity Programs Start with People

Cybersecurity works best when it works with people, not against them — and that’s exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by:

  • Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such as culture, trust, usability, or resilience
  • Communicating the relationship between HCC and existing NIST cybersecurity guidelines and frameworks
  • Assisting organizations in implementing and enhancing HCC within their cybersecurity programs.

But we can’t do that without you. We invite you to read the blog introducing our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and submit your feedback via human-cybersec@nist.gov by September 30, 2026.

Visit the NIST Human-Centered Cybersecurity Website to learn more about this and other HCC efforts.

 Read the Blog

Workshop Report on Rolling Next-Generation Secure Hardware into Standards | NIST IR 8615 Available

NIST announces the publication of NIST Internal Report (IR) 8615, Workshop on Rolling Next-Generation Secure Hardware into Standards, which documents the outcomes from the Sustainable Hardware Security (SUSHI@NIST) Workshop held on January 26, 2026. The workshop brought together stakeholders from industry, academia, and government to identify priorities and actionable approaches to strengthen hardware security across the semiconductor ecosystem.

The report highlights a growing consensus that next-generation hardware security requires a coordinated, evidence-based approach spanning the full life cycle, from silicon and intellectual property through manufacturing, deployment, operation, and end-of-life.

The participants identified five priority areas:

  1. Unified standards and governance, including common terminology, interoperable trust models, tiered assurance approaches, and guidance for emerging technologies (e.g., chiplets, AI hardware, post-quantum computing)
  2. Embedding security, provenance, and traceability throughout the semiconductor life cycle through mechanisms such as cryptographic identities, SBOMs, attestation, verification, and life cycle-aware access controls
  3. Strong supply chain security (e.g., verifiable components) and economic incentives, such as procurement requirements, public-private partnerships, industry consortia, and pilot programs
  4. Scalable verification and validation for continuous assurance, including AI-assisted analysis, formal methods, fuzzing, standardized testing, and resilience evaluation
  5. Workforce development and collaboration across industry, academia, government, standards organizations, and research programs

Together, these recommendations provide a foundation for advancing interoperable, measurable, and sustainable hardware security practices across the semiconductor ecosystem.

Read More

Guide to Operational Technology (OT) Security: NIST Requests Comments on Draft SP 800-82r4

NIST has released the initial public draft of Special Publication (SP) 800-82r4 (Revision 4), Guide to Operational Technology (OT) Security, which provides guidelines for improving the security of OT systems while addressing their unique performance, reliability, and safety requirements.

OT encompasses a broad range of programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems (ICS), building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems.

This fourth revision of SP 800-82 provides an overview of OT and typical system topologies, identifies common threats to organizational mission and business functions supported by OT, describes typical vulnerabilities in OT, and provides recommended security safeguards and countermeasures to manage the associated risks. 

Updates in this revision include:

  • Expanded introduction to OT sectors to include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT) and cloud convergence
  • Restructured around the NIST Cybersecurity Framework (CSF) 2.0, including a reorganization of the previous risk management section to focus on the CSF Govern Function
  • Expanded discussion of how OT risk management aligns with broader enterprise risk management, as described in NIST IR 8286r1
  • Discussion of the adoption of the NIST Risk Management Framework (RMF) in Appendix F
  • Expanded guidelines for implementing OT security controls, including asset management and network monitoring and detection
  • Security architecture guidelines focused on protecting system management functions and applying zero trust principles

The comment period on this initial public draft is open now through November 30, 2026. See the publication details for a copy of the draft and instructions for submitting comments.

NOTE: A call for patent claims is included in this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.

View the Publication

MS-ISAC CYBERSECURITY ADVISORY – Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution – PATCH NOW

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.

SYSTEMS AFFECTED:

  • Helidon, versions 3.0.0-3.2.20, 4.0.0-4.5.4
  • Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.0.0, 14.1.2.1.0
  • Oracle Agile Engineering Data Management, version 6.2.1
  • Oracle Agile PLM, version 9.3.6
  • Oracle Agile PLM MCAD Connector, version 3.6
  • Oracle Application Testing Suite, version 13.3.0.1
  • Oracle Autonomous Health Framework, versions 26.2, 26.3.1, 26.5.3, 26.8
  • Oracle Banking Branch, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Corporate Lending, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Origination, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle Banking Treasury Management, versions 14.5.0.0.0-14.9.0.0.0
  • Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0
  • Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0
  • Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 25.2.201, 26.1.200
  • Oracle Communications MetaSolv Solution Module – ASR, version 70.0.0
  • Oracle Communications Operations Monitor, version 6.1
  • Oracle Communications Service Catalog and Design, versions 8.0-8.3
  • Oracle Communications Unified Assurance, versions 6.1.1-7.0.0
  • Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Database Server, versions 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3
  • Oracle E-Business Suite, versions 12.2.3-12.2.15, V16
  • Oracle Enterprise Manager Base Platform, versions 13.5, 24.1
  • Oracle Enterprise Manager for Fusion Middleware, versions 13.5, 24.1
  • Oracle Enterprise Manager for Oracle Database, version 24.1
  • Oracle Forms, versions 12.2.1.19.0, 14.1.2.0.0
  • Oracle Fusion Middleware Control, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle GraalVM Enterprise Edition, version 21.3.19.1
  • Oracle GraalVM for JDK 17, version 23.0.13.1
  • Oracle GraalVM for JDK 21, version 23.1.12.1
  • Oracle Hyperion Data Relationship Management, version 11.2.26.0.0
  • Oracle Hyperion Financial Management, version 11.2.26.0.0
  • Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle Internet Directory, versions 12.2.1.4.0, 14.1.2.1.0
  • Oracle JDeveloper, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Middleware Common Libraries and Tools, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • Oracle Platform Security for Java, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle Product Lifecycle Analytics, version 3.6.1
  • Oracle Utilities Network Management System, versions 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 25.12.0.0.0-25.12.0.0.3
  • Oracle VM VirtualBox, version 7.2.16
  • Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0
  • Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
  • PeopleSoft Enterprise CC Common Application Objects, version 9.2
  • PeopleSoft Enterprise FIN Engineering Brazil, version 9.1
  • PeopleSoft Enterprise FIN Inventory Brazil, version 9.1
  • PeopleSoft Enterprise PeopleTools, versions 8.61-8.63
  • PeopleSoft Enterprise PRTL Interaction Hub, version 9.1
  • Service Delivery Platform, versions 12.2.1.4.0, 14.1.2.0.0
  • Siebel Applications, versions 17.0-26.7

RISK:
Government:

  • Large and medium government entities: High
  • Small government: High

Businesses:

  • Large and medium business entities: High
  • Small business entities: High

Home Users: Low

TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution.

A full list of all vulnerabilities can be found in the Oracle link in the References section.

Successful exploitation of the most severe of these vulnerabilities could result in remote code execution in the context of the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

RECOMMENDATIONS:
We recommend the following actions be taken:

  • Apply appropriate updates provided by Oracle to vulnerable systems immediately after appropriate testing. (M1051:Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.5 : Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
    • Safeguard 12.1: Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
    • Safeguard 18.1: Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
    • Safeguard 18.2: Perform Periodic External Penetration Tests: Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
    • Safeguard 18.3: Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026:Privileged Account Management)
    • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
    • Safeguard 5.4: Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
    • Safeguard 5.5: Establish and Maintain an Inventory of Service Accounts: Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently.
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050:Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Block execution of code on a system through application control, and/or script blocking. (M1038:Execution Prevention)
    • Safeguard 2.5: Allowlist Authorized Software: Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
    • Safeguard 2.6: Allowlist Authorized Libraries: Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, .so, etc., files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.
    • Safeguard 2.7: Allowlist Authorized Scripts: Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
  • Use capabilities to prevent suspicious behavior patterns from occurring on endpoint systems. This could include suspicious process, file, API call, etc. behavior. (M1040:Behavior Prevention on Endpoint)
    • Safeguard 13.2: Deploy a Host-Based Intrusion Detection Solution: Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported.
    • Safeguard 13.7: Deploy a Host-Based Intrusion Prevention Solution: Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017:User Training)
    • Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.


REFERENCES:

Oracle:
https://www.oracle.com/security-alerts/cspusep2026.html

Using AI for CSF 2.0 Analysis and Reporting—New NIST CSF Quick-Start Guide

NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and Reporting. This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.  

The document’s purpose is to: 

  • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes 
  • Identify current state of practice for AI prompt engineering in CSF implementation and analysis 

While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation.   

This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more.  

  • USE CASE 1 illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and risk governance in alignment with the CSF 2.0 outcomes.  
  • USE CASE 2 illustrates how to produce a draft Organization Current State Profile– mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.  
  • USE CASE 3 illustrates how to draw upon internal and industry references to create a draft CSF target state profile describing desired outcomes to meet mission objectives, stakeholder expectations, address the risk landscape, and fulfill requirements. 

Use case examples illustrate a possible approach and are not prescriptive assessment or assurance methodologies.  

Submit Your Comments:  

The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.    

View and Comment

Multi-Cloud Architecture Challenges: Draft IR 8613 Available for Public Comment

NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges and highlights areas where additional community research could meaningfully reduce risk.

The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos. The most significant structural challenge areas are:

  • Security-significant differences in cloud-native services across providers
  • Organizational logistics and staffing complexity across heterogeneous environments
  • Difficulty in implementing centralized security capabilities across provider boundaries

These structural gaps are most acute in five areas: (1) identity and access management, (2) telemetry and logging, (3) configuration and change management, (4) data protection, and (5) compliance and authorization.

Submit Your Comments:

NIST invites input from federal agencies, industry partners, researchers, and the broader cybersecurity community. The public comment period is open through October 5, 2026. See the publication details for a copy of the draft and instructions for submitting comments.

Read More

Comment Now: Initial Non-Access Stratum Message Security White Paper

The NIST National Cybersecurity Center of Excellence (NCCoE) released the initial public draft Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security, which describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.

You still have two weeks left to submit your feedback!

This white paper is part of the NCCoE’s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.

Background

Current 5G standards include specifications to address cybersecurity and privacy challenges present in previous generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network—the Initial NAS Message—was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.

Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.

This white paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.

By demonstrating security features on our operational 5G Testbed, we aim to deliver real-world implementation insights to advance 5G security and inform the next generation of wireless security. 

Submit Your Feedback!

This white paper is available for public comment through September 7, 2026. Don’t miss your chance to provide feedback! Visit the NCCoE project page to learn more and download the White Paper today.

Comment Now

Using Informative References for Cybersecurity Risk Management

The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guide, has published. Thank you to all who provided comments during the public comment period.  

This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement. 

View the Quick-Start Guide