AZTCOFWCYBER SECURITY SOLUTIONS
Back to insights ↗
NewsAZTCOFW Editorial

Late-September security watch: Citrix flaws, Apple updates and Microsoft token theft

A security briefing for the week of 24 September 2026, updated with Citrix's 27 September NetScaler advisory. Three separate issues call for different responses.

Published
Editorial illustration
Editorial illustration · AZTCOFW

Citrix: patch exposed NetScaler systems

Citrix's 27 September bulletin lists eight NetScaler ADC and Gateway vulnerabilities. Citrix says exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated deployments. The first affects default deployments and can allow unauthenticated remote code execution. The second concerns DTLS-enabled deployments, including VPN virtual servers where DTLS is enabled by default. Inventory affected appliances, follow Citrix's current fixed-build matrix, and investigate possible compromise as well as patching. This advisory was published after 24 September and is included as a later update.

Apple: security updates and an account authentication fix

Apple's 14 September iOS 27 and iPadOS 27 security notes include CVE-2026-20683, an authentication issue in the Sign in with Apple flow that could let a malicious app access a user's Apple Account. Apple says it addressed the issue with improved state management. Use Apple's security releases page to identify the newest supported update for each device and verify installation. Apple's advisory does not describe this as a confirmed mass token-theft campaign.

Microsoft: device-code phishing steals sign-in tokens

Microsoft's 22 September research describes EvilTokens, a phishing service that abuses the legitimate device-code sign-in flow. Victims can complete a real sign-in and still give an attacker usable tokens. Microsoft reports mailbox access, email exfiltration and persistence through malicious inbox rules or device registration. Review unusual device-code sign-ins, token exchange, new inbox rules and new devices. If an account is affected, follow Microsoft's token-theft response guidance, including revoking refresh tokens and checking mailbox changes.

What security teams should do

Assign owners to the three tracks: NetScaler exposure and patch status; Apple device update coverage; and Microsoft 365 identity investigation. Keep the evidence and response separate. A firewall can help restrict malicious destinations and expose network activity, but account-token revocation and vendor patches must happen in the affected platforms.

Sources & references

  1. Citrix — NetScaler security bulletin CTX697096 (27 September 2026) ↗
  2. Apple — iOS 27 and iPadOS 27 security content (14 September 2026) ↗
  3. Apple — security releases ↗
  4. Microsoft — EvilTokens device-code phishing research (22 September 2026) ↗

Continue reading

All insights ↗

AZTCOFW / Contact

Make your next connection
a more secure one.

Tell us what you’re building. We’ll help you plan the security around it.

Talk to a specialist ↗
Privacy policy ↗

Search

Search website content and the English knowledge base.

Start with a product, topic or question.