// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Thursday, October 8, 2026

● 4 CRITICAL● 3 WARNING● 7 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

“Identify every Citrix NetScaler instance in your environment right now — internal + client-facing — and either patch to the latest firmware or remove external access within 24 hours.”

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE— 2 items
WARNING☁️ M365/Azure

Azure OpenAI & Cognitive Services Intermittent Failures — Sweden Central (Sept 30–Oct 1)

Azure OpenAI, Azure AI Foundry, and Cognitive Services in the Sweden Central region suffered repeated waves of intermittent request failures and increased latency between 22:43 and 02:33 UTC on September 30–October 1. Microsoft mitigated the incident within approximately four hours but the recurrence across multiple windows suggests ongoing instability in the region. MSPs managing AI workloads or Copilot dependencies on Azure OpenAI should verify service health and consider fallback region routing.

Read more →
WARNING☁️ M365/Azure

Microsoft Exchange Server EoP Patch — October 2026 Patch Tuesday (CVE-2026-96940)

October 2026 Patch Tuesday is a light release — just 4 KB updates fixing a single CVE: CVE-2026-96940, a Microsoft Exchange Server Elevation of Privilege vulnerability rated CVSS 8.8 (High). The flaw is not currently on the CISA KEV list and has not been publicly exploited, but its high CVSS and 'exploitation more likely' rating make it a priority. Affected builds include Exchange Server 2016 CU23, 2019 CU14/CU15, and Subscription Edition RTM — deploy KB5129955–5129958 this maintenance window.

Read more →
🔐 SECURITY— 3 items
CRITICAL🔐 Security

CRITICAL: Citrix NetScaler SAML Zero-Day CVE-2026-88779 — CISA KEV, Patch Now

Citrix published emergency bulletin CTX697174 on October 3–4 for CVE-2026-88779, a CVSS 8.7 memory overflow in NetScaler ADC and Gateway appliances configured for SAML SP or IdP — confirmed as a zero-day already being actively exploited in targeted attacks. CISA added it to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 7, 2026. Workaround: upgrade immediately to NetScaler ADC 14.1-73.41 or 13.1-64.28 (FIPS: 14.1-73.41 FIPS / 13.1-37.282); note that admins who patched last month for earlier CVEs may need to patch again.

Read more →
CRITICAL🔐 Security

CRITICAL: Citrix NetScaler RCE Zero-Days CVE-2026-88771 & CVE-2026-88772 — Both on CISA KEV

Two additional critical NetScaler zero-days — CVE-2026-88771 (CVSS 9.5, improper input validation leading to RCE in default config) and CVE-2026-88772 (CVSS 9.5, memory overflow leading to RCE in DTLS config) — were confirmed exploited in the wild and added to CISA KEV. Citrix released patches on September 27, 2026, but organisations are urged to verify they applied the latest builds as the October CVE-2026-88779 fix supersedes prior updates. This marks three actively exploited NetScaler zero-days in ten days.

Read more →
CRITICAL🔐 Security

Citrix NetScaler SAML Zero-Day CVE-2026-88779 Actively Exploited — Emergency Patches Released

Citrix released emergency security updates on 5 October 2026 for a zero-day SAML vulnerability in NetScaler (CVE-2026-88779) that attackers are actively exploiting in the wild. The flaw allows unauthenticated attackers to bypass SAML authentication on affected NetScaler ADC and Gateway appliances. Organisations should apply the emergency update immediately; no viable workaround exists short of patching — disabling SAML is only feasible if not in use.

Read more →
🔥 NETWORKING— 2 items
CRITICAL🔥 Networking

CRITICAL: Citrix NetScaler SAML Zero-Day RCE Scope Under Investigation — Broader Than DoS

Security researchers examining CVE-2026-88779 exploitation attempts found crafted authentication requests embedding shell command strings in SAML assertion payloads, raising concern that the confirmed denial-of-service flaw may also be leverageable for remote code execution. Citrix is actively investigating; the pattern mirrors how an earlier NetScaler flaw (CVE-2025-6543) was initially characterised as DoS before RCE was confirmed. Workaround: apply vendor patches in CTX697174 immediately and do not wait for the RCE assessment to conclude.

Read more →
WARNING🔥 Networking

SonicWall SMA1000 SQL Injection CVE-2026-4112 and Auth-Bypass Flaws Patched

SonicWall released patches for four vulnerabilities in SMA1000 series appliances, including a high-severity SQL injection bug (CVE-2026-4112) that allows read-only administrators to escalate to full admin rights. Additional flaws enable remote attackers to enumerate SSL VPN credentials or bypass TOTP authentication. SonicWall reports no confirmed exploitation, but urges immediate firmware updates — check psirt.sonicwall.com for the latest version guidance.

Read more →
← Wednesday, October 7, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice