Virtualization Watch Issue 003: Citrix NetScaler Zero-Days Hit Over a Weekend; Sidero Builds a Hypervisor into Talos Linux
September 28, 2026 · Biweekly · Coverage window: 9/14-9/27 From the Editor This issue opens with a severe vulnerability chain disclosed over a weekend. On Saturday (9/26), the security firm watchTowr issued a sudden public warning: two NetScaler remote code execution flaws with no patches yet were already being exploited in the wild. The Dutch national cyber security center (NCSC-NL) went further, privately telling some organizations to take their appliances offline. On Sunday (9/27), Citrix published advisory CTX697096, fixing eight CVEs at once - two of them zero-days rated CVSS v4 9.5. CISA added both to its Known Exploited Vulnerabilities catalog the same day, leaving federal agencies three days to patch. The same week, Sidero Labs put a hypervisor directly into Talos Linux, managing containers and virtual machines through one operating system and one API. Incident response and the evolution of the hypervisor itself are this issue's two threads. In This Issue Citrix NetScaler: Two Zero-Days Land Over a Weekend, with a 3-Day KEV Deadline On September 27 (Sunday), Citrix published advisory CTX697096, fixing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them were confirmed to be exploited in the wild: - CVE-2026-88771 (CVSS v4 9.5): improper input validation lets an unauthenticated attacker execute arbitrary commands. Every deployment model is affected, including default configurations - no optional feature has to be enabled. - CVE-2026-88772 (CVSS v4 9.5): memory overflow leading to remote code execution or denial of service. The trigger is DTLS, and DTLS is on by default for VPN virtual servers. The fixes are in 14.1-73.37 and later, or 13.1-64.23 and later; 13.0 and 12.1 are end-of-support and need to be migrated. The same advisory covers six further flaws (CVE-2026-88773 through 88778), including a request-smuggling issue rated 9.3. On September 26, watchTowr issued its public warning (official FAQ), saying the vulnerabilities came out of a forensic investigation and that the information was credible. That same day, some administrators reported receiving "take the appliance offline" advice relayed by vendors and security teams, tracing back to an NCSC-NL private pre-notification. On September 27, the day the advisory landed, CISA added both CVEs to the KEV catalog, giving federal agencies until September 30 - three days. For context, this is the third time NetScaler has entered the KEV catalog this year: CVE-2026-8452 in August, then CVE-2026-19490 on September 9. NetScaler appliances sit at the enterprise network edge, handling VPN, load balancing, and authentication - once compromised, they serve as a pivot into the internal network. Sources: The Hacker News (9/27), Citrix CTX697096, watchTowr FAQ Sidero Ships Talos Hypervisor: a Hypervisor Built into the Kubernetes Operating System On September 14, Sidero Labs announced native hypervisor capability in Talos Linux (official press release): enterprises can manage containers and virtual machines with one operating system and one API, without running Kubernetes for one job and a virtualization stack for another, and without having to learn KubeVirt first to run VMs. The same release adds direct container scheduling without Kubernetes, aimed at single-node edge deployments. The essentials: - Fully open source, still under MPL-2.0. The alpha and a public demo arrive at TalosCon 2026 (Amsterdam, October 15-16), with general availability targeted for December 2026. - A second announcement the same day explains where the resources come from: Sidero Labs is being acquired by Yardi, a real-estate software company (official blog 9/14). Yardi was already running Talos in production; the company says the team will keep operating independently and that the open-source roadmap is unchanged. - The next day (9/15), Sidero rolled out a commercial edition, Talos Enterprise Linux: 24/7 support SLAs, FIPS builds, SBOM/VEX artifacts, and CVE-response SLAs - covering what a compliance-driven buyer normally has to assemble from several vendors. Talos's positioning is distinct: rather than building another vSphere, it makes the hypervisor a native capability of an immutable infrastructure operating system. ZSvirt Community News: First Open-Source Monthly Report and Roadmap This publication is produced by the ZSvirt community. This section covers the publisher's own news. On September 15, ZSvirt published the first issue of its open-source monthly report, Around the World). It looks back at the first month since the full open-source release on August 12 (GPL-3.0) and publishes the product roadmap for the first time. Second-Half 2026 Roadmap (First Public Release) On hardware and release process: aarch64 support is under evaluation, and GPU components are on the plan; a formal release process (GitHub releases and tags) will follow, making version history traceable. Product work spans five areas: | Area | Planned work | |---|---| | Security | VM disk encryption, VM migration encryption | | DRS and migration | Data-disk-only migration; live and cold migration for SAN, cold migration for NFS | | ZMigrate 2.1 | Pre-migration checks to head off complex migration risk, with a simpler, smarter flow | | Operations | New metrics: VM CPU ready time, disk read/write latency, network packet loss, host CPU ready time; finer-grained external syslog forwarding; NVMe and FC IOPS/latency monitoring; a bundled QXL driver in VMTools | | Inventory | Storage and VM registration extended to same-site scenarios | A reminder: Storytellers Phase 1 (the YouTube challenge) closes tomorrow, 9/28. Creators interested in taking part should sign up at GitHub Discussion #8 before the deadline. Sources: ZSvirt open-source monthly report issue 1 (9/15), GitHub: ZSvirt/zsvirt Product & Version News Incus 7.5 / 7.5.1: Eleven Security Fixes, OVN Child Networks, GPU P2P (September 25) Incus 7.5 landed on September 25 with a dense changelog: - Security: eleven fixes at once, including a serious btrfs path traversal (CVE-2026-85185 / CVE-2026-85526) and arbitrary writes through symlinks in the migration data stream. This was a coordinated disclosure with Canonical, whose LXD 5.21.8 / 5.0.10 / 4.0.14 shipped the matching fixes on September 23; the same fixes are in LXD 6.9. - Networking: OVN child networks, for more flexible logical topologies. - Operations: instances can move across projects, and live migration is stronger. - GPU: NVIDIA GPUDirect P2P support ( nvidia.clique 0-15), so multi-GPU passthrough no longer takes a detour. - Platform: a new NetBSD guest agent. The 7.5.1 that followed is not a follow-up fix release - it is a re-release, after 7.5.0 failed to produce release artifacts. VirtualBox 7.2.18 → 7.2.20: Two Maintenance Updates in a Week (September 15, September 22) Oracle shipped VirtualBox 7.2.18 on September 15 with eleven fixes: a blue screen after saving state on Windows 11 on ARM guests, VDI image corruption, and adaptation for the RHEL 10.3 kernel, among others. That month's Oracle Critical Patch Update also fixed CVE-2026-87279. On September 22 came 7.2.20, an urgent release targeting a regression 7.2.18 introduced (GitHub issue gh-870, VERR_SUP_VP_FOUND_EXEC_MEMORY at startup). With two releases in one week, desktop virtualization users should go straight to 7.2.20. Source: VirtualBox News Kata Containers 4.2.0: 80-Plus Changes (September 15) Kata Containers 4.2.0 arrived on September 15 with more than 80 changes: the guest rootfs moves to Ubuntu 26.04; the toolchain moves to Go 1.26.7 / Rust 1.96; the Rust runtime (runtime-rs) gains fd-passing block-device and VFIO device support for QEMU; and the Dragonball sandbox gains virtio-rng. Worth a look for confidential-container and lightweight-sandbox users. Harvester v1.9.0: a Whole-Stack Upgrade (September 16) SUSE's hyperconverged platform Harvester v1.9.0 shipped on September 16: the foundation moves to RKE2 v1.36, Longhorn v1.12, Rancher v2.15, and Kube-OVN v1.16, on an SLE Micro 6.2 base, with a preview of the Longhorn v2 storage engine. Fix releases are moving fast - v1.9.1-rc1 on September 17 and rc2 on September 23 - so GA should not be far off. Cloud Vendors: AWS T8i and Google X5 Both Reach GA - AWS EC2 T8i is generally available (9/17): the burstable line gets a generational refresh, with up to 1.25x the network bandwidth, up to 2.4x the EBS bandwidth, and up to 30 percent better price-performance than T3. It launches in 16 regions, in sizes from nano to medium. Sources: AWS What's New, AWS blog - Google Cloud X5 is generally available (9/25): per-instance memory rises from 32 TB on X4 to 48 TB, aimed at very large-scale SAP HANA scale-up and RISE with SAP. Source: Compute Engine release notes Gartner Publishes Its First Server Virtualization Platforms Magic Quadrant (9/14) On September 14, Gartner published the Magic Quadrant for Server Virtualization Platforms (analysts: Tony Harvey, Daniel Bowers, Paul Delory, Tony Iams, Owen Marino), evaluating 17 vendors on Ability to Execute and Completeness of Vision - the first industry-wide assessment since Broadcom acquired VMware and licensing models were upended. Per Virtualization Review's reading of the report, Gartner holds that Broadcom's acquisition of VMware has "reinvigorated" the server virtualization market (Virtualization Review, 9/23). Teasers and Snapshots - QEMU 11.1.2 entered freeze on September 26 with 92 patches queued; the release is planned for September 28, just past this window. - OpenStack 2026.2 "Hibiscus" is on schedule for September 30. - Linux 7.3-rc5 shipped on September 27 with KVM fixes (rc4 was September 20). - An "Orphaned VMs" RFC from the KVM community (9/20, authored by Pasha Tatashin) would let virtual machines keep running while the host kernel is updated in place, pushing downtime toward zero. - KVM Forum 2026 is set for November 12-13 in Vancouver. Community Buzz HN: virtio-nvgpu Reaches 98-100 Percent of Native GPU Performance Ins
Comments
No comments yet. Start the discussion.