0–4 hours — CRITICAL: Alex’s threshold stands, but “isolate” should mean removing vulnerable management interfaces from untrusted reachability—not blindly powering off the SD-WAN estate. If staffing forces an order, first block external access to Catalyst SD-WAN Manager, because CVE-2026-76504 is actively exploited, can yield netadmin control, and has no workaround; then drain and isolate exposed NetScaler nodes. For Cisco, preserve manager, proxy, and WAF logs; hunt j_security_check and URI-encoding anomalies, correlating them with subsequent privileged API activity or configuration changes. Keep this as a hunt until correlated—the pre-baseline false-positive rate is unknown, with a production acceptance target below 5%. If restricting the management plane would interrupt essential WAN service, permit only named jump hosts while preparing a patched replacement; this is temporary containment, not a workaround. Fixed Cisco releases include 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. [3] For NetScaler, preserve evidence before changes and hunt for command-bearing PPE failures, including “unexpectedly died” and “missed too many heartbeats.” CVE-2026-88771 is reported as pre-auth command injection, while CVE-2026-88772 is a DTLS-dependent memory-overflow issue; both are reported under active exploitation. [1][2] Rebuild from clean media if those indicators, persistence, unauthorized configuration changes, or unexplained privileged activity appear—or if logging gaps prevent independent integrity validation. Patch-only is acceptable solely where complete exploitation-window telemetry exists and integrity is independently established.
By 24 hours — HIGH: For NetScaler, patch every node, but do not return a suspect appliance to service merely because the software is current; rebuild triggered systems and rotate credentials or trust material accessible from them. [1][2] For Cisco, test the applicable fixed train on standby or staging, upgrade, and restore broader management connectivity only after log review and configuration-integrity checks; a positive j_security_check chain or insufficient evidence keeps the manager isolated and moves it to trusted rebuild. For exposed GitHub/cloud/npm credentials, do not use the reported exposure count as the incident scope: identify which secrets belong to the organization, then revoke confirmed active, long-lived, privileged tokens first. Freeze package publishing or deployment only for pipelines holding those credentials; examine GitHub, CI, npm, and cloud audit histories for use, copying, or privilege escalation before issuing replacements. Public reporting identifies more than 500,000 active credentials in public GitHub repositories and separate npm activity targeting developer and cloud credentials, but neither figure establishes an individual organization’s blast radius. [4][5][6]
By 7 days — MEDIUM: Complete NetScaler and Cisco fleet coverage, validate HA/failover, document every integrity decision, and retain evidence from rebuilt systems. For the credential thread, replace long-lived CI and cloud secrets with short-lived, narrowly scoped identities where supported, review downstream repositories and environments reached by each secret, and add secret scanning and issuance ownership controls. Apple CVE-2026-86950: put vendor-fixed updates through an expedited canary and broad deployment cycle, but the new public crash PoC alone does not justify displacing tonight’s actively exploited network-control work or prove reliable code execution. [7]