type: cve ยท created: 2026-07-31 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: false
Citrix NetScaler memory-overread vulnerability exploited in the wild as part of autonomous AI-driven cyber attacks. A Chinese-speaking threat actor using DeepSeek via the Hermes Agent framework leveraged CVE-2026-3055 to exfiltrate data from three organisations, alongside command execution on 11 systems. The vulnerability was one of eight CVEs across seven exploit tracks used in the campaign reported by Palo Alto Networks Unit 42.
See: Cyber Digest โ 2026-08-01