• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • About Me
  • Privacy Policy
  • Media Mentions

PenTestIT.com

Your source for Detection Engineering, Security Research and Adversary Simulation

  • Search Engine Dorks
  • RSS feed
You are here: Home / Archives for Vulnerability Management

Vulnerability Management Archives:

Cyber Threat Intelligence

Analysis: CVE-2026-88771 and CVE-2026-88772

This is my analysis of the Citrix NetScaler ADC/Gateway CVE-2026-88771 & CVE-2026-88772 vulnerabilities along with hunting & detection guide

Posted: Sep 28, 2026 by Mayuresh @pentestit Leave a Comment
Updated: Sep 29, 2026

Analysis: CVE-2026-88771, CVE-2026-88772

Citrix published fixes for eight NetScaler ADC and Gateway CVEs today - September 27, 2026, in bulletin CTX697096. Two of them, CVE-2026-88771 and CVE-2026-88772, were exploited before the bulletin went out. As a result, CISA added both to KEV the same day. This is my analysis of the two vulnerabilities, collation of data from multiple sources and the steps you can take to Read more about Analysis: CVE-2026-88771 and CVE-2026-88772

Cyber Threat Intelligence

Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

This blog is my interpretation of the Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Posted: Sep 9, 2026 by Mayuresh @pentestit
Updated: Sep 12, 2026

Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Back after a hiatus the Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority blog. Last time I did this was Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority. This time around, I am doing two things differently. I am ranking every priority against CISA BOD 26-04. Interested? Read on! Read more about Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Detection Engineering

Essential Detection Engineering Metrics

This is a list of essential detection engineering metrics.

Posted: Sep 1, 2026 by Mayuresh @pentestit
Updated: Sep 9, 2026

Essential Detection Engineering Metrics

You have prioritized your threat detection backlog, but now want to quantify the progress. Throughout my career leading multiple threat detection engineering teams, I have relied on well-defined metrics to measure outcomes, demonstrate program value, and drive continuous improvement. In this post, I outline the detection engineering metrics I consider most important, spanning Read more about Essential Detection Engineering Metrics

Detection Engineering

“Severity” or “Expected Severity” for Prioritization?

This post introduce the concept of "Expected Severity" for threat prioritization.

Posted: Apr 26, 2026 by Mayuresh @pentestit 704 views
Updated: Sep 6, 2026

In one of my last post - Prioritizing a Threat Detection Backlog, I talked about prioritizing your threat detection backlog. It is true when you run a program in an organization. However, when you consume security content from another organization, severity is often generalized. This is where, the concept of expected severity can help and I trust should be used more often. Let Read more about “Severity” or “Expected Severity” for Prioritization?

Vulnerability Management

Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority

This blog is my interpretation of the Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority.

Posted: Mar 11, 2026 by Mayuresh @pentestit 1,153 views
Updated: Sep 12, 2026

Microsoft Patch Tuesday March 2026

This Microsoft Patch Tuesday March 2026 release addressed 93 vulnerabilities across Windows, Office, SQL Server, .NET, and Azure. Interestingly, two CVEs were publicly disclosed pre‑patch CVE‑2026‑21262 (SQL Server EoP) and CVE‑2026‑26127 (.NET DoS). However, unlike last month, no March CVE is confirmed exploited in the wild as of today. What is unusual is the fact that six of Read more about Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority

Primary Sidebar

Add PenTestIT as a preferred source on Google

Categories

  • Adversary Emulation
  • Cyber Threat Intelligence
  • Detection Engineering
  • Offensive Security
  • Open Source
  • Penetration Testing
  • Tools
  • Vulnerability Management
  • Vulnerability Research
  • Web Application Security

Archives

  • September 2026
  • April 2026
  • March 2026
  • February 2026
  • August 2022
  • July 2020

Copyright © 2026 - PenTestIT.com | Information shared to be used for LEGAL purposes only!