Executive assessment
Today's brief leads with Citrix NetScaler: Improper Restriction of Operations within the Bounds of a Memory Buffer. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 10 should lead instead: it is a high-severity set of YesWiki vulnerabilities with PoC available, no listed fixed version, and specific interim controls. The listed Citrix NetScaler item is high severity, but exploitation, fixed version, and controls are all unknown in the brief. Themes: PoC-backed web and API flaws; Missing fixes with compensating controls; Authorization and information disclosure issues. Patch order: Finding 10 (High-severity multiple YesWiki vulnerabilities have PoC available, no listed fixed version, and listed controls for ActivityPub, the inbox endpoint, and page-write access); Finding 13 (High-severity Phproject object-level authorisation flaw has PoC available and a listed fixed version, Phproject 1.8.7); Finding 05 (High-severity PictShare information disclosure has PoC available, no listed fixed version, and listed reverse-proxy blocks for unauthenticated API access); Finding 07 (High-severity Mooncake memory-exhaustion flaw has PoC available, no listed fixed version, and listed controls to restrict handshake RPC ports and monitor RSS growth); Finding 09 (High-severity Zebra consensus-divergence vulnerability has PoC available; no fixed version or controls are listed, so it needs early triage).
Finding 01 — Citrix NetScaler: Improper Restriction of Operations within the Bounds of a Memory Buffer
What changed: CISA added CVE-2026-88779 (Citrix NetScaler) to the Known Exploited Vulnerabilities catalogue: Improper Restriction of Operations within the Bounds of a Memory Buffer, CVSS v4.0 8.7.
Technical evidence: CVE-2026-88779; CVSS v4.0 8.7; weakness CWE-119; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Action: Map CVE-2026-88779 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-88779)
Finding 02 — Linux kernel: Race Condition
What changed: NVD records CVE-2026-98163 (Linux kernel): Race Condition, CVSS v3.1 7.0; affected: OSV lists the affected range as introduced in Linux kernel 6.19.0 and fixed in 7.2.8.
Technical evidence: CVE-2026-98163; CVSS v3.1 7.0; weakness CWE-362; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: OSV lists the affected range as introduced in Linux kernel 6.19.0 and fixed in 7.2.8. ([osv.dev](https://osv.dev/vulnerability/CVE-2026-98163))
Fix: Linux kernel 7.2.8. ([osv.dev](https://osv.dev/vulnerability/CVE-2026-98163))
Action: Map CVE-2026-98163 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-98163)
Finding 03 — wolfSSL: Improper Certificate Validation
What changed: MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert().
Technical evidence: CVE-2026-93302; CVSS v4.0 8.3; weakness CWE-295; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Rebuild with --disable-openssl-compatible-defaults and do not load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). CISA ADP Vulnrichment reports no exploitation. ([github.com](https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.4-stable), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-93302))
Affected: wolfSSL versions 5.3.0 to 5.9.2. ([github.com](https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.4-stable))
Fix: wolfSSL 5.9.4. ([github.com](https://github.com/wolfSSL/wolfssl/releases/tag/v5.9.4-stable))
Action: Map CVE-2026-93302 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93302)
Finding 04 — Multiple vulnerabilities in JetBrains YouTrack
What changed: CVE coverage: CVE-2026-100262, CVE-2026-100276. The cited advisories disclose: missing authorisation allowed users with read-only project access to overwrite project notification templates; guest users could remove a workflow action's visibility restriction and run the action.
Technical evidence: CVE-2026-100262; CVSS v3.1 7.6; weakness CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: On YouTrack Cloud, keep the guest account banned; for the template issue, deactivate Per-project Notification Template Customization so editing is limited to users with Low-level Admin Write. CISA ADP Vulnrichment reports no exploitation for either CVE. ([jetbrains.com](https://www.jetbrains.com/help/youtrack/cloud/managing-guest-users.html.md), [jetbrains.com](https://www.jetbrains.com/help/youtrack/cloud/project-notification-templates.html.md), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-100262), +1 more)
Panel assessment: Patch this week: there is no reported exploitation and CISA rates both issues non-automatable with partial impact, but they are authorisation bypasses that let low-privilege access change YouTrack behaviour, so the blast radius is project configuration and workflow actions rather than a broad unauthenticated compromise. (priority: this week)
Action: Map CVE-2026-100262 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-100262)
Finding 05 — PictShare: Insufficiently Protected Credentials
What changed: NVD records CVE-2026-104051 (PictShare): Insufficiently Protected Credentials, CVSS v4.0 8.8; affected: PictShare 2.0.0 and later, before 3.7.1.
Technical evidence: CVE-2026-104051; CVSS v4.0 8.8; weakness CWE-522; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patched, block unauthenticated access to /api/info/<hash> and /api/delete/<code>/<hash> at the reverse proxy. The wvllxe GitHub repository publishes a read-only-by-default PoC with an opt-in deletion test. ([github.com](https://github.com/wvllxe/CVE-2026-104051-pictshare-info-disclosure), [vulncheck.com](https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api))
Affected: PictShare 2.0.0 and later, before 3.7.1. ([vulncheck.com](https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api))
Action: Map CVE-2026-104051 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104051)
Finding 06 — JetAppointment plugin for WordPress: Cross-site Scripting
What changed: The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Technical evidence: CVE-2026-93875; CVSS v3.1 7.2; weakness CWE-79; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Temporarily block unauthenticated requests to the jet_engine_form_booking_submit endpoint. CISA ADP Vulnrichment reports exploitation as "none". ([wordfence.com](https://www.wordfence.com/threat-intel/vulnerabilities/id/758f9402-33f4-40a6-a021-bf689d3b4a1b?source=cve), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-93875), [crocoblock.com](https://crocoblock.com/wp-content/uploads/jet-changelog/jet-appointments-booking-site.json))
Fix: JetAppointment 2.5.3. ([crocoblock.com](https://crocoblock.com/wp-content/uploads/jet-changelog/jet-appointments-booking-site.json))
Action: Map CVE-2026-93875 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93875)
Finding 07 — Mooncake transfer engine: Allocation of Resources Without Limits or Throttling
What changed: Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
Technical evidence: CVE-2026-103761; CVSS v4.0 8.7; weakness CWE-770; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict the handshake RPC port range 15000-17000 to trusted peers and monitor the engine process's RSS for rapid growth. Mooncake issue #4445 reports a socket-loop proof of concept that accepted 2,979 frames in about 20 seconds and increased victim RSS from 50 MB to 2,672 MB. ([github.com](https://github.com/kvcache-ai/Mooncake/issues/4445))
Action: Map CVE-2026-103761 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-103761)
Finding 08 — Ghost: Observable Discrepancy
What changed: Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
Technical evidence: CVE-2026-104416; CVSS v4.0 7.7; weakness CWE-203; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Affected: >= 4.39.0, < 6.64.0 ([github.com](https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v))
Fix: 6.64.0 ([github.com](https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v))
Action: Map CVE-2026-104416 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104416)
Finding 09 — Zebra: Improper Verification of Cryptographic Signature
What changed: Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Technical evidence: CVE-2026-104437; CVSS v4.0 8.3; weakness CWE-347; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-104437 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104437)
Finding 10 — Multiple vulnerabilities in YesWiki
What changed: CVE coverage: CVE-2026-104445, CVE-2026-104457. The cited advisories disclose: an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor.
Technical evidence: CVE-2026-104445; CVSS v4.0 8.8; weakness CWE-290; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable ActivityPub for Bazar forms or block POST requests to /api/forms/{formId}/actor/inbox. Restrict page-write access to authenticated accounts to remove the default unauthenticated path to the filtertags injection. ([api.github.com](https://api.github.com/repos/YesWiki/yeswiki/security-advisories/GHSA-rm6r-grfg-4v78), [api.github.com](https://api.github.com/repos/YesWiki/yeswiki/security-advisories/GHSA-p87r-f4x4-8r4g))
Affected: CVE-2026-104445 was confirmed on doryphore-dev at commit 418805a762fa207ef2be99edf902b154b362e7de; CVE-2026-104457 was verified on release tag v4.6.6. ([api.github.com](https://api.github.com/repos/YesWiki/yeswiki/security-advisories/GHSA-rm6r-grfg-4v78), [api.github.com](https://api.github.com/repos/YesWiki/yeswiki/security-advisories/GHSA-p87r-f4x4-8r4g))
Panel assessment: Patch now: this combines unauthenticated exposure on common/default paths, a working SQL-injection exploit detail, and an ActivityPub route that can alter or delete federated content, so the blast radius is both database access and content integrity. (priority: patch now)
Action: Map CVE-2026-104445 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104445)
Finding 11 — Paperwork: SQL Injection
What changed: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection.
Technical evidence: CVE-2026-85215; CVSS v3.1 7.1; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-85215 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-85215)
Finding 12 — Dogtag PKI (pki-core): Authentication Bypass by Spoofing
What changed: A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate.
Technical evidence: CVE-2026-104988; CVSS v3.1 8.1; weakness CWE-290; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Disable Basic authentication for all EST users by removing the 'UserPasswords' field from user entries in the EST DS server. Alternatively, enforce mutual TLS client certificates for EST fullcmc enrolment. ([access.redhat.com](https://access.redhat.com/security/cve/CVE-2026-104988), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-104988))
Affected: Red Hat Certificate System 10 and 11; Red Hat Enterprise Linux 10. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-104988))
Action: Map CVE-2026-104988 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104988)
Finding 13 — Phproject: Missing Authorization
What changed: NVD records CVE-2026-104991 (Phproject): Missing Authorization, CVSS v4.0 7.1; affected: Phproject versions up to and including 1.8.6.
Technical evidence: CVE-2026-104991; CVSS v4.0 7.1; weakness CWE-862; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until upgrading, block the three affected REST routes at a reverse proxy: GET /issues/{id}.json and GET or POST /issues/{id}/comments.json. ([github.com](https://github.com/Alanaktion/phproject/security/advisories/GHSA-mpq9-v47x-3hw8), [api.github.com](https://api.github.com/repos/Alanaktion/phproject/security-advisories/GHSA-mpq9-v47x-3hw8))
Affected: Phproject versions up to and including 1.8.6. ([api.github.com](https://api.github.com/repos/Alanaktion/phproject/security-advisories/GHSA-mpq9-v47x-3hw8))
Fix: Phproject 1.8.7. ([api.github.com](https://api.github.com/repos/Alanaktion/phproject/security-advisories/GHSA-mpq9-v47x-3hw8))
Action: Map CVE-2026-104991 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104991)
Finding 14 — geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
What changed: GitHub Advisory Database published GHSA-mhvh-fq92-pfmr for CVE-2026-77387 (geopy): Inefficient Regular Expression Complexity, CVSS v3.1 4; affected: geopy versions up to and including 2.4.1.
Technical evidence: CVE-2026-77387; CVSS v3.1 4; weakness CWE-1333; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Limit coordinate strings to a maximum of 256 characters before passing them to geopy. ([github.com](https://github.com/advisories/GHSA-mhvh-fq92-pfmr), [api.github.com](https://api.github.com/advisories/GHSA-mhvh-fq92-pfmr), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-77387))
Affected: geopy versions up to and including 2.4.1. ([api.github.com](https://api.github.com/advisories/GHSA-mhvh-fq92-pfmr))
Fix: geopy 2.5.0. ([api.github.com](https://api.github.com/advisories/GHSA-mhvh-fq92-pfmr))
Action: Map CVE-2026-77387 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-mhvh-fq92-pfmr)
Finding 15 — modelcontextprotocol mcp-server-fetch and mcp-server-everything: Server-Side Request Forgery
What changed: A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool.
Technical evidence: CVE-2026-104120; CVSS v4.0 6.9; weakness CWE-918; technical confidence Medium.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Constrain mcp-server-fetch outbound HTTP/S requests by blocking loopback, link-local, cloud-metadata, 0.0.0.0/8, ULA/RFC1918 and other private or reserved ranges, and disable redirects or revalidate every hop. For server-everything, treat an empty GZIP_ALLOWED_DOMAINS allowlist as deny-all and apply equivalent network filtering. ([github.com](https://github.com/modelcontextprotocol/servers/issues/4492#issuecomment-5535722880))
Action: Map CVE-2026-104120 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-104120)