.png)
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: September 21 – 28, 2026
GreyNoise saw exploitation attempts on Citrix NetScaler CVE-2026-88771 on 24 September, more than three days before public disclosure. Behavioral detections labeled it malicious within seconds. Read the blog for the full analysis >
GreyNoise saw CVE-2026-88771 exploitation attempts against a Swarm participant sensor on 24 September, more than three days before public disclosure. Exploitation attempts from new sources began within a day of disclosure. Read Swarming Against Citrix 0-Day Exploitation.
CISA listed CVE-2026-94127, an unauthenticated code execution flaw in the BIG-IP Access Policy Manager, in its KEV catalog with a three-day federal deadline. One of the ten sources checking for it sent about 99% of all checks. BIG-IP discovery traffic more than tripled.
Adversaries attempted an administrator takeover flaw from 68 sources on one day, then a sandbox escape from 79 sources the next. Both sit in the KEV catalog. About two thirds of those 79 also attempted a CyberPanel flaw.
GreyNoise observed an average of 3,551 malicious sources per full day on the Next.js middleware bypass, a flaw outside the KEV catalog. A payload firing alongside it arrived entirely from two large cloud and content delivery networks.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.
At The Edge is GreyNoise's weekly intelligence brief produced exclusively for customers incorporating complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations. At The Edge Clear is a preview highlighting a couple insights and is available to the public.
Analysis Period: September 21 – 28, 2026
GreyNoise saw exploitation attempts on Citrix NetScaler CVE-2026-88771 on 24 September, more than three days before public disclosure. Behavioral detections labeled it malicious within seconds. Read the blog for the full analysis >
GreyNoise saw CVE-2026-88771 exploitation attempts against a Swarm participant sensor on 24 September, more than three days before public disclosure. Exploitation attempts from new sources began within a day of disclosure. Read Swarming Against Citrix 0-Day Exploitation.
CISA listed CVE-2026-94127, an unauthenticated code execution flaw in the BIG-IP Access Policy Manager, in its KEV catalog with a three-day federal deadline. One of the ten sources checking for it sent about 99% of all checks. BIG-IP discovery traffic more than tripled.
Adversaries attempted an administrator takeover flaw from 68 sources on one day, then a sandbox escape from 79 sources the next. Both sit in the KEV catalog. About two thirds of those 79 also attempted a CyberPanel flaw.
GreyNoise observed an average of 3,551 malicious sources per full day on the Next.js middleware bypass, a flaw outside the KEV catalog. A payload firing alongside it arrived entirely from two large cloud and content delivery networks.
.png)
GreyNoise customers get detailed briefs with complete IOCs, infrastructure attribution, detection guidance, and role-based recommendations every week.
Request a demo to learn more about GreyNoise's data and intelligence.