At The Edge Clear: September 21 – 28, 2026

Table of Contents
Loading nav...

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

An Adversary Tried a Citrix Zero-Day Before Disclosure

Analysis Period: September 21 – 28, 2026

GreyNoise saw exploitation attempts on Citrix NetScaler CVE-2026-88771 on 24 September, more than three days before public disclosure. Behavioral detections labeled it malicious within seconds. Read the blog for the full analysis >

‍

By The Numbers:

  • 3+ days — Citrix exploitation attempts before public disclosure.
  • Over 3x — BIG-IP discovery traffic vs. the prior week.
  • 52 of 79 — CrushFTP burst sources that also tried CyberPanel.
  • At least 4x — Daily Next.js bypass sources vs. late August.

Preview Findings:

1. New sources attempted the Citrix flaw within a day of disclosure

GreyNoise saw CVE-2026-88771 exploitation attempts against a Swarm participant sensor on 24 September, more than three days before public disclosure. Exploitation attempts from new sources began within a day of disclosure. Read Swarming Against Citrix 0-Day Exploitation.

2. Sources checked BIG-IP for a newly listed KEV flaw

CISA listed CVE-2026-94127, an unauthenticated code execution flaw in the BIG-IP Access Policy Manager, in its KEV catalog with a three-day federal deadline. One of the ten sources checking for it sent about 99% of all checks. BIG-IP discovery traffic more than tripled.

3. Adversaries targeted CrushFTP in two single-day bursts

Adversaries attempted an administrator takeover flaw from 68 sources on one day, then a sandbox escape from 79 sources the next. Both sit in the KEV catalog. About two thirds of those 79 also attempted a CyberPanel flaw.

4. Next.js daily bypass sources ran at least 4x the August level

GreyNoise observed an average of 3,551 malicious sources per full day on the Next.js middleware bypass, a flaw outside the KEV catalog. A payload firing alongside it arrived entirely from two large cloud and content delivery networks.

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍

Read the transcript

‍

At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.

An Adversary Tried a Citrix Zero-Day Before Disclosure

Analysis Period: September 21 – 28, 2026

GreyNoise saw exploitation attempts on Citrix NetScaler CVE-2026-88771 on 24 September, more than three days before public disclosure. Behavioral detections labeled it malicious within seconds. Read the blog for the full analysis >

‍

By The Numbers:

  • 3+ days — Citrix exploitation attempts before public disclosure.
  • Over 3x — BIG-IP discovery traffic vs. the prior week.
  • 52 of 79 — CrushFTP burst sources that also tried CyberPanel.
  • At least 4x — Daily Next.js bypass sources vs. late August.

Preview Findings:

1. New sources attempted the Citrix flaw within a day of disclosure

GreyNoise saw CVE-2026-88771 exploitation attempts against a Swarm participant sensor on 24 September, more than three days before public disclosure. Exploitation attempts from new sources began within a day of disclosure. Read Swarming Against Citrix 0-Day Exploitation.

2. Sources checked BIG-IP for a newly listed KEV flaw

CISA listed CVE-2026-94127, an unauthenticated code execution flaw in the BIG-IP Access Policy Manager, in its KEV catalog with a three-day federal deadline. One of the ten sources checking for it sent about 99% of all checks. BIG-IP discovery traffic more than tripled.

3. Adversaries targeted CrushFTP in two single-day bursts

Adversaries attempted an administrator takeover flaw from 68 sources on one day, then a sandbox escape from 79 sources the next. Both sit in the KEV catalog. About two thirds of those 79 also attempted a CyberPanel flaw.

4. Next.js daily bypass sources ran at least 4x the August level

GreyNoise observed an average of 3,551 malicious sources per full day on the Next.js middleware bypass, a flaw outside the KEV catalog. A payload firing alongside it arrived entirely from two large cloud and content delivery networks.

‍

‍

Want the full brief?

GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.

‍Request a demo to learn more about GreyNoise's data and intelligence.

‍

‍

‍

‍

‍