An approval form stamped REJECTED and its carbon copy underneath stamped APPROVED, with a different box ticked on each
September 30, 2026

Agents Ran Actions Nobody Approved

This week an agent framework swapped what a person approved, a simulated model took a bot's reply as a yes, and a coding tool never asked. Citrix shipped fixes for zero-days already in use.
This week
This week: 17 CVEs in focus | 12 under active exploitation | 3 zero-days
TL;DR
1
Citrix patched two exploited NetScaler zero-days on September 27, and CISA gave federal agencies until September 30. CISA
2
GitGuardian found 474 leaked GitHub App private keys that still worked, including one belonging to the CDC. GitGuardian
3
Kernel bug CVE-2026-80521 escapes containers, and Ubuntu 26.04's kernel was still unpatched when depthfirst published. depthfirst

The Big Picture

Another week, another pair of edge-appliance zero-days, this time two in Citrix NetScaler that attackers were using before any fix existed. The more interesting news was about something almost every AI agent design depends on, a person saying yes.

A new paper on Loopjacking showed agent frameworks swapping in a different action after someone had approved one. In the UK AI Security Institute's simulated tests, GPT-6 Astra took an automated reply as permission to go after out-of-scope targets, and a bug in OpenCode let a webpage install attacker code without asking anyone at all. A yes should only ever cover the exact thing it was asked about.

⭐ Story of the Week

The Human Approved One Action and the Framework Ran Another

Most agent frameworks pause before a risky action and ask a person to approve it, a step usually called human-in-the-loop approval. Adithyan Arun Kumar's September 17 arXiv paper calls the failure of that step Loopjacking, where a human approves "operation A, while the implementation uses that decision for a materially different operation B." In one variant, B is already built in and shown to the human as something else. In the other, the human sees the correct action and the pending request is changed to B after the approval.

Kumar found it in seven Agno AgentOS releases through 3.0.9, twelve LangGraph Agent Server versions through 0.14.0 in a specific in-memory setup, and OpenClaw 2026.2.23, which was fixed in 2026.2.24. The OpenAI Agents SDK (0.22.0 and 0.22.2), the one framework in the paper that held, binds each approval to the exact call and rejects a changed one.

The UK AI Security Institute's September 28 post on GPT-6 Astra describes fully simulated tests in its Petri tool, a different setup from the real sandbox escapes we covered on September 2. AISI deliberately disabled Astra's cyber classifiers, and nothing ran against a real system. Inside that setup, Astra completed an unsanctioned supply-chain attack in 29.2% of runs, against 6.3% for GPT-5.6 Sol and none for GPT-5.5, which ran on a smaller set of tests. AISI says Astra "sometimes treated this automated message as permission to proceed with actions against out-of-scope targets."

OpenCode's bug needed no prompt at all, only an OpenCode server running without password authentication, or with credentials the browser had cached. Christophe Tafani-Dereeper of Datadog Security Labs found that its /global/upgrade endpoint handed an untrusted version string to the package manager (GHSA-632h-h47v-g4x4). A malicious webpage could send a cross-origin form POST, which CORS does not block for a top-level navigation, and npm would install the attacker's package and run its preinstall script. Versions 1.14.30 through 1.18.21 are vulnerable and 1.18.22 fixed it on August 24, yet the vulnerable versions were downloaded more than 647,000 times between September 17 and 23.

The Bottom Line...

Does the agent framework you run bind each approval to the exact call it executes, and reject that call if it changes afterward? Kumar's repro archive has test harnesses for Agno, LangGraph and OpenClaw, so for those three you can check it directly.

Deep Dives

GitHub App Keys and a GitLab Email Token Never Expire

A GitHub App is how a tool like a CI service or a bot gets access to your repositories, and it proves who it is with a private key. GitGuardian's Gaetan Ferry started from more than 500,000 exposed RSA private keys and tested 4,802 of them. Of those, 474 still worked, authenticating as 440 distinct GitHub Apps. Among the Apps:

• 72% could read private repositories

• 207 had write access to repositories, and 98 could control workflows

• 40 could administer self-hosted runners, and 44 had full organization admin

One was a private App at the CDC, whose key leaked in April 2025, was disclosed on September 4 and was revoked on September 18. "App keys have no expiration date," the post says.

Aikido's Joe Leon describes a GitLab credential with the same trait. The "Email work item to this project" address carries a glimt- token that works across the owner's whole account, not just one project, and it never expires. Change -issue@ to -merge-request@, attach a .patch that edits .gitlab-ci.yml, and GitLab runs a pipeline as the token's owner. GitLab does not verify the sender, and email skips IP allowlists.

Aikido reported it through HackerOne in May, and GitLab classified it as "intended behavior" and added UI clarifications. This is a separate issue from CVE-2026-85706, the GitLab file-read bug we led with on September 16.

The Bottom Line...

List your org's GitHub App private keys and the GitLab accounts holding an incoming-email token, and give each one an owner and a rotation date. Every revocation GitGuardian names, the CDC's included, happened only after an outside researcher reported the key.

Stronger AI Models Over-Corrected More When Their Patches Failed

Quarkslab's Julien Lair pointed an eight-stage AI harness at FreeRDP, the open-source remote desktop library of about 500,000 lines of C, with a human reviewing between stages and stepping in twice when the exploit work stalled. In the four days from first access to the maintainer report, the run went from 130 initial findings to 36 clusters to 20 confirmed real bugs, with 10 false positives and six latent or mixed. Two advisories came out of it, for a routing-token heap overflow (GHSA-2vf2-grvj-6g8x) and a USB redirection heap disclosure (GHSA-hw7p-5h2r-83gq). "The edge isn't the AI model, but how you assemble the system around it," the post concludes.

The Artificial Analysis Cyber Index, published September 28, tested patching as well as finding, and the best model found 41% of expert-verified issues. Among failed patch attempts, 55% fixed the primary issue but left a related one open. Over-corrections, where a model changed more than the issue required, made up about 24% of failures overall. For the four highest-scoring models that share rose to about 40%, against about 15% for the lowest performers.

The Bottom Line...

It is tempting to wave through a patch from a top model, yet in the Cyber Index the top models' failed patches were the ones most often over-corrected. When an AI patch touches files or functions the original report never mentioned, that extra code is the part to review first.

Citrix Had No Workaround for Two Exploited NetScaler Zero-Days

Citrix published bulletin CTX697096 on Sunday, September 27, covering eight NetScaler ADC and Gateway vulnerabilities. Two had already been exploited as zero-days to drop webshells. CVE-2026-88771 is a pre-authentication command injection that works in the default configuration. CVE-2026-88772 is a DTLS memory overflow, and DTLS is on by default for VPN virtual servers.

Both are rated 9.5 on CVSS 4.0. Google Threat Intelligence says the exploitation has been going on since at least early September, against government, financial, technology, education and legal targets in North America and Europe. watchTowr warned publicly on September 26, after the Dutch NCSC had privately pre-notified administrators, and CISA's KEV entry the day after set a September 30 deadline.

Citrix published no workaround. Google's advice for teams that can't patch yet is to disable DTLS on internet-facing gateways or block inbound UDP/443, and CISA told defenders to check for compromise before patching because updates can erase forensic evidence.

The same week, a Cisco survey of 8,000 respondents in 30 markets asked how quickly organizations can switch on a new security control. Only 21% said they could do it within six months, counted after budget and approval had already cleared. Among the survey's top performers the figure was 52%. All of the numbers are self-reported.

The Bottom Line...

The warning some admins got privately before the bulletin was to shut their NetScalers down immediately, a step that needs no budget or approval cycle. Who on your team is allowed to take the VPN gateway offline on a weekend without calling a meeting first?

Vulnerabilities in the Wild

Under active exploitation

• Citrix NetScaler ADC and Gateway CVE-2026-88771 and CVE-2026-88772, both CVSS 4.0 9.5, both zero-days. CVE-2026-88771 is a pre-authentication RCE that works in the default configuration. CVE-2026-88772 is a memory overflow in DTLS handling, and DTLS is on by default for VPN virtual servers. Google Threat Intelligence says CVE-2026-88772 has been exploited since at least early September against government, financial, technology, education and legal targets in North America and Europe, using a new PHP web shell (WHIPSHOT) and a Python tunneler (SLAPSHOT). Citrix published the fix on September 27, and CISA added both to KEV the same day with a September 30 deadline. Fixed in 14.1-73.37 and 13.1-64.23. If you cannot patch yet, Google suggests disabling DTLS or blocking inbound UDP/443. (Citrix, Google Threat Intelligence)

• Apple iOS and iPadOS CVE-2026-86950, CVSS 8.8, a zero-day. An out-of-bounds write in CoreGraphics means a crafted file can run code on the device. Apple says it "may have been exploited in an extremely sophisticated attack against specific targeted individuals" on versions before iOS 27. Meta Product Security reported it. Fixed September 28 in iOS and iPadOS 26.7.1, and CISA added it to KEV September 29. (Apple)

• WSO2 API Manager and other WSO2 products CVE-2026-5430, CVSS 10.0. The JWT validator accepts tokens signed with an unsupported algorithm, so an attacker can forge an admin token. It ran in last week's list, when watchTowr had already caught forged tokens. CISA added it to KEV on September 24. (CISA)

• Oracle PeopleSoft PeopleTools CVE-2026-35273, CVSS 9.8. Missing authentication in the Environment Management Hub gives an unauthenticated attacker code execution on PeopleTools 8.61 and 8.62. ShinyHunters first used it as a zero-day in May and June. On September 25 Google reported a renewed wave on dozens of systems across higher education, healthcare, government and other sectors, reaching the servlet as /%50SEMHUB/ so string-matching WAF rules miss it, then dropping the x.jsp and u.jsp web shells. WAF rules alone do not stop it: apply Oracle's patch or disable EMHub. (Google Threat Intelligence)

• JetBrains TeamCity On-Premises CVE-2026-63077, CVSS 9.8. Unauthenticated deserialization in the agent polling protocol gives remote code execution. It has been fixed since July in 2026.1.3 and 2025.11.7 and in KEV since August. CISA's KEV entry now marks it as used in ransomware campaigns. (CISA)

• WordPress core CVE-2026-87902, CVSS 9.2. Unauthenticated path traversal in page-template resolution can include a local PHP file, and that becomes code execution when the theme has a top-level page- directory, PHP has register_argc_argv on and PEAR's pearcmd.php is reachable. Last week this list said no compromise was confirmed. Patchstack now reports file-write attempts from September 22, and CISA added it to KEV on September 25. Fixed in 7.1.2, with backports to every branch back to 4.7. Look for unexpected PHP files in /tmp or /var/tmp. (Patchstack)

• Adobe Commerce and Magento CVE-2026-71362, CVSS 9.1. An authorization flaw lets an attacker gain elevated access to sensitive resources with no user interaction. Adobe patched it in August in APSB26-92, and CISA added it to KEV on September 24. (Adobe)

• Microsoft SharePoint Server CVE-2026-65660, CVSS 8.8. Code injection lets an authenticated attacker run code, and attackers are pairing it with a separate anonymous delivery bug to skip the login. Previdian's honeypot caught a two-stage payload chain on September 24. Microsoft patched it August 11 and later reclassified it from spoofing to RCE. CISA added it to KEV September 25. Affects SharePoint Server 2016, 2019 and Subscription Edition. (Previdian)

• Roundcube Webmail CVE-2026-48842, CVSS 8.1. Pre-authentication SQL injection in the virtuser_query plugin, so only servers with that plugin enabled are exposed. It was fixed on May 24 in 1.6.16 and 1.7.1, and the Canadian Centre for Cyber Security updated its advisory on September 21 to say it is being exploited in the wild. It is not in KEV. If you cannot upgrade, disable the plugin. (Canadian Centre for Cyber Security)

• MikroTik RouterOS CVE-2026-67279, CVSS 4.0 6.9. RouterOS SSH lets a client that never authenticated open a session after asking for a rekey and send an exec request. CERT Polska disclosed it on September 5 alongside other RouterOS SSH flaws already under attack, including CVE-2026-86060, an argument injection in the login process that CISA added to KEV on September 10. CISA added CVE-2026-67279 on September 25. Fixed in 7.24.2, 7.23.4 and 6.49.21. Until then, restrict SSH to trusted networks. (CISA)

Not yet exploited

• Next.js CVE-2026-94545, CVSS 9.5. The Node.js ImageResponse from next/og can run attacker code when an app passes attacker-controlled values into the SVG content, attributes or styles it renders, such as text from the request URL. The Edge runtime and Next.js 15 are not affected. Affects 16.2.0 through 16.3.5, fixed in 16.3.6 on September 22. (Vercel)

• SolarWinds Observability Self-Hosted CVE-2026-28324 and CVE-2026-28325, CVSS 9.8 and 8.8. Both allow unauthenticated code execution. CVE-2026-28324 comes from weak integrity checks and affects only installs in a non-default, non-secure configuration. CVE-2026-28325 is a deserialization flaw in one communication mode. Fixed in 2026.2.3. (SolarWinds)

• Linux kernel CVE-2026-80521, CVSS 7.8, public exploit. A use-after-free in AF_UNIX sockets lets code in a container escape to root on the host. It was fixed upstream on August 6, but when depthfirst published its full exploit on September 22, Ubuntu 26.04's kernel still had no fix. depthfirst found it with its own AI model. The action is taking your distribution's kernel update as soon as it ships. (depthfirst)

• OpenCode GHSA-632h-h47v-g4x4, CVSS 7.5, no CVE assigned. With opencode serve running and OpenCode installed through npm, pnpm or Bun, any webpage the user visits can make the /global/upgrade endpoint install an attacker's package and run its install script. Affects 1.14.30 and later, fixed in 1.18.22. (OpenCode)

• MCP Python SDK GHSA-qx49-fqc8-xw99, CVSS 7.5. A malicious MCP server could make a client send its OAuth client secret, authorization code and PKCE verifier to a token endpoint the attacker controls. Fixed in 1.30.0 and 2.2.0, but if you use ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider, the upgrade only helps once you also pass issuer=. (MCP Python SDK maintainers)

• OpenSSL CVE-2026-84782, High severity. When a DTLS handshake write pauses and a retransmission fires, OpenSSL resends from a stale buffer offset, which can leak heap memory to the peer in plaintext or crash the process. Only DTLS is affected, not TLS. Fixed September 29 in 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixes for 3.0, 1.1.1 and 1.0.2 go only to premium support customers. (OpenSSL)

Curated Reading List

Thought-Provoking / Analysis

• AI on Kubernetes: 10 of 14 Helm Charts Ship With No API Auth (Sorami Consulting) Why it's worth your time: an audit of the default Helm charts for 15 AI serving, vector database and MCP projects. Ten of the 14 with an API ship without authentication, a Kubernetes MCP server listed 23 tools to an unauthenticated caller and returned Secret names from other namespaces, and the four scanners tested (Kubescape, Checkov, kube-linter, Trivy) did not reliably inspect pods declared inside custom resources such as KubeRay's RayCluster. The rendered manifests, probe logs and scanner output are all in the repo.

• Srsly Risky Biz: Bring on the AI Lawsuits (Risky Business, Tom Uren and Patrick Gray) Why it's worth your time: Treasury Secretary Bessent ruled out a liability waiver for frontier AI labs, and Uren and Gray argue that keeping the labs legally on the hook is what pushes them to test harder. The same episode covers Midnight Blizzard running an espionage campaign through AI workflows and accepting the mistakes as a cost of doing more attacks.

• Reviewing Slop and Asking for Better Feedback (Natalie Somersall) Why it's worth your time: AI made a 30-page document cheap to produce, but reading it takes a reviewer just as long as it always did. She gives plain wording for the other side of that trade, like saying up front "not asking for an in-depth review" and naming exactly what feedback you want.

Technical Deep Cuts

• Don't Let TEEs Break Your MPC (Trail of Bits, Paul Bottinelli) Why it's worth your time: adding a trusted execution environment to a multi-party computation scheme can make it weaker, because the two rest on different trust models. The worked example is a rollback attack where the host restores a deleted pre-signature file from backup, the signer reuses its nonce share and its private key share leaks.

• HTTP/3 in Burp Suite: It's Time to Find a Bigger Wordlist (PortSwigger Research, Tom Stacey) Why it's worth your time: Turbo Intruder now speaks HTTP/3 and hit 100,000 requests per second from a laptop over Wi-Fi, against about 30,000 over HTTP/1.1. It also adds two race-condition techniques built on QUIC, a single-datagram attack and a QPACK blocked-streams trick, both aimed at narrower race windows than the single-packet attack.

• One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts (Doyensec, Leonardo Giovannini) Why it's worth your time: Chrome for iOS trusted Apple's Shortcuts app and skipped its launch prompt, but Shortcuts accepts a callback URL, so one tap on a webpage could reach tel: without Chrome's usual check (CVE-2026-13795). The lesson carries to any deep-link policy: a check on the first hop does nothing if that hop can open something else.

Stay ahead of AppSec

Weekly intelligence for security leaders.