CISA orders feds to patch actively exploited Citrix flaw by Thursday
2026-03-31T07:23:30Z•366d21395e6dccd562a02cede871d8f49da9b938724130f4a6369562307718f5
active-exploitationbig-ipcarecloudcisacitrixclickfixcve-2026-3055data-breacheuropa.euf5fbi-emailfile-read-vulnerabilityforticlientfortinethandalainfinity-stealermacos-securitynetscalerpypi-backdoorrceroadk1llshinyhunterssupply-chaintelnyxwordpress-smart-slider
What happened
A cluster of high‑impact incidents and actively exploited vulnerabilities dominated reporting: CISA ordered federal agencies to urgently patch a critical, actively exploited Citrix NetScaler memory flaw (CVE-2026-3055). Attackers are also exploiting critical F5 BIG-IP and Fortinet FortiClient EMS flaws to deploy webshells and other payloads. Multiple breaches and supply‑chain incidents were disclosed, including a CareCloud patient-data breach, a Europa.eu compromise claimed by ShinyHunters, the Handala-linked compromise of FBI Director Kash Patel’s personal email, and a backdoored Telnyx PyPI‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 366d21395e6dccd562a02cede871d8f49da9b938724130f4a6369562307718f5
- Enrichment time
- 2026-03-31T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.