Bg Shape
Image

Citrix NetScaler Mass Exploitation, Cisco's 9.8 CVE & Revolut Breached Again

Robert Kehoe
Chief Technology Officer
Published:
October 2, 2026

This week's Risk Radar: Citrix NetScaler vulnerabilities move from disclosure to mass exploitation in under 24 hours, Cisco's SD-WAN racks up its eighth vulnerability of the year with a critical 9.8 CVSS score, and Revolut discloses another data breach, this time rooted in a supplier's supplier rather than its own systems.

Citrix NetScaler Under Mass Exploitation

On Saturday, a security firm disclosed two separate attacks against Citrix NetScaler products, affecting both the ADC and Gateway lines. By Sunday, these exploits had already been adopted at scale by attackers, impacting thousands of deployments worldwide.

What to do:
Patch any NetScaler ADC or Gateway deployment immediately, rotate all associated accounts, and take a snapshot of your logs now for forensic analysis before evidence ages out.

Cisco SD-WAN's Eighth Vulnerability This Year

Cisco has confirmed its eighth SD-WAN vulnerability of the year, carrying a CVSS score of 9.8. This level of recurring critical findings in a single product line should already have patch cycles on a short leash.

What to do:
Upgrade to the patched release immediately. Hunt your logs for POST requests, particularly URL-encoded requests to the affected security-check endpoint, and cross-reference known indicators of compromise from the associated suspicious IP addresses.

Revolut Breached Again, This Time Through a Supplier's Supplier

Revolut has suffered another data breach, though not directly: a US-based data broker used by one of Revolut's suppliers was itself breached, exposing data belonging to Irish Revolut users, including phone numbers, email addresses, physical addresses and employer details. The timing was pointed, with our own Robert Kehoe speaking on third-party and supply chain risk at the Business Post Cybersecurity Summit in Croke Park just days earlier.

What to do:
Risk-assess and manage data flowing not just to your direct suppliers but to their suppliers in turn, and maintain a tracked inventory of every connection to your critical ICT providers.

Stay safe, and share this with your team.

Read Our Latest Blogs

Blog Image
Citrix NetScaler Mass Exploitation, Cisco's 9.8 CVE & Revolut Breached Again

Citrix NetScaler flaws face mass exploitation within a day of disclosure, Cisco's SD-WAN scores its eighth CVE of the year, and Revolut is breached again via a third-party supplier.

Blog Image
6 best MDR and XDR platforms for MSSPs in 2026

Compare six MDR and XDR platforms for MSSPs on multi-tenancy, compliance mapping and response speed, from CrowdStrike to Smarttech247 VisionX.

Blog Image
Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Microsoft rushes an emergency patch after last week's update broke Remote Desktop and hypervisor stability, Revolut discloses a process breach affecting 680+ high-net-worth clients, and Cisco scores another perfect 10 CVSS.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Citrix NetScaler Mass Exploitation, Cisco's 9.8 CVE & Revolut Breached Again

Risk Radar
Vulnerabilities and Exposure
Data Security and Privacy
Supply Chain and Third Party Risks
Robert Kehoe
Chief Technology Officer
October 2, 2026

This week's Risk Radar: Citrix NetScaler vulnerabilities move from disclosure to mass exploitation in under 24 hours, Cisco's SD-WAN racks up its eighth vulnerability of the year with a critical 9.8 CVSS score, and Revolut discloses another data breach, this time rooted in a supplier's supplier rather than its own systems.

Citrix NetScaler Under Mass Exploitation

On Saturday, a security firm disclosed two separate attacks against Citrix NetScaler products, affecting both the ADC and Gateway lines. By Sunday, these exploits had already been adopted at scale by attackers, impacting thousands of deployments worldwide.

What to do:
Patch any NetScaler ADC or Gateway deployment immediately, rotate all associated accounts, and take a snapshot of your logs now for forensic analysis before evidence ages out.

Cisco SD-WAN's Eighth Vulnerability This Year

Cisco has confirmed its eighth SD-WAN vulnerability of the year, carrying a CVSS score of 9.8. This level of recurring critical findings in a single product line should already have patch cycles on a short leash.

What to do:
Upgrade to the patched release immediately. Hunt your logs for POST requests, particularly URL-encoded requests to the affected security-check endpoint, and cross-reference known indicators of compromise from the associated suspicious IP addresses.

Revolut Breached Again, This Time Through a Supplier's Supplier

Revolut has suffered another data breach, though not directly: a US-based data broker used by one of Revolut's suppliers was itself breached, exposing data belonging to Irish Revolut users, including phone numbers, email addresses, physical addresses and employer details. The timing was pointed, with our own Robert Kehoe speaking on third-party and supply chain risk at the Business Post Cybersecurity Summit in Croke Park just days earlier.

What to do:
Risk-assess and manage data flowing not just to your direct suppliers but to their suppliers in turn, and maintain a tracked inventory of every connection to your critical ICT providers.

Stay safe, and share this with your team.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365