Late-September security watch: Citrix flaws, Apple updates and Microsoft token theft
A security briefing for the week of 24 September 2026, updated with Citrix's 27 September NetScaler advisory. Three separate issues call for different responses.

Citrix: patch exposed NetScaler systems
Citrix's 27 September bulletin lists eight NetScaler ADC and Gateway vulnerabilities. Citrix says exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated deployments. The first affects default deployments and can allow unauthenticated remote code execution. The second concerns DTLS-enabled deployments, including VPN virtual servers where DTLS is enabled by default. Inventory affected appliances, follow Citrix's current fixed-build matrix, and investigate possible compromise as well as patching. This advisory was published after 24 September and is included as a later update.
Apple: security updates and an account authentication fix
Apple's 14 September iOS 27 and iPadOS 27 security notes include CVE-2026-20683, an authentication issue in the Sign in with Apple flow that could let a malicious app access a user's Apple Account. Apple says it addressed the issue with improved state management. Use Apple's security releases page to identify the newest supported update for each device and verify installation. Apple's advisory does not describe this as a confirmed mass token-theft campaign.
Microsoft: device-code phishing steals sign-in tokens
Microsoft's 22 September research describes EvilTokens, a phishing service that abuses the legitimate device-code sign-in flow. Victims can complete a real sign-in and still give an attacker usable tokens. Microsoft reports mailbox access, email exfiltration and persistence through malicious inbox rules or device registration. Review unusual device-code sign-ins, token exchange, new inbox rules and new devices. If an account is affected, follow Microsoft's token-theft response guidance, including revoking refresh tokens and checking mailbox changes.
What security teams should do
Assign owners to the three tracks: NetScaler exposure and patch status; Apple device update coverage; and Microsoft 365 identity investigation. Keep the evidence and response separate. A firewall can help restrict malicious destinations and expose network activity, but account-token revocation and vendor patches must happen in the affected platforms.


