BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

A Sylius Customer Login Could Open the Admin API

In vulnerable Sylius shops, one reused email address can turn a customer token into administrator access while a separate flaw can mark an enlarged order paid.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched

Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and says attackers are already exploiting two of them on unmitigated systems. This is not a routine patch bundle. One of the exploited flaws gives an unauthenticated attacker a path to arbitrary command execution across every customer-managed deployment, including default configurations.

The critical issue is CVE-2026-88771, an improper input-validation vulnerability with a CVSS v4 score of 9.5. Citrix says no optional feature needs to be enabled. If the appliance is running an affected build, the precondition is met.

Citrix has also observed exploitation of CVE-2026-88772, another CVSS 9.5 flaw. It is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers unless administrators explicitly turn it off.

Citrix's CTX697096 security bulletin states plainly that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments. It does not identify an actor, campaign, victim count, exploitation start date or indicators of compromise.

That absence of public detail must not be mistaken for an absence of risk. Patching closes the known vulnerable paths, but it cannot prove that an internet-facing appliance was clean before the upgrade. Organisations with exposed NetScaler gateways should run the upgrade and compromise assessment as parallel workstreams.

The urgency is amplified by where these products sit. NetScaler Gateway controls remote access and often fronts authentication, VPN and application traffic. An unauthenticated command-execution path at that boundary…

27 Sep 2026 · 5 min read

A Wrong Password Could Run Code Inside hMailServer

A wrong password can become code before the login succeeds. Progressive Robot’s hMailServer 6.3.4 release on 27 September fixes that risk in its Windows 6.x project. The issue should not be generalised…

27 Sep 2026 · 2 min read

A Botnet Seller Is Offering to Drain Your AI Budget

Qrator Research Labs has examined an advertised Windows botnet called x47.c whose seller offers an AI API drain mode. It requires the operator to supply a valid account key and sends billable…

27 Sep 2026 · 3 min read

Even Protected Files Can Give Away What You Are Doing

Researchers at Graz University of Technology show that filesystem notifications can reveal user activity even when a process cannot read the underlying file. Their ACM CCS 2026 paper covers Linux, Windows, macOS…

27 Sep 2026 · 3 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.