This month: 9 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2015-3306
ProFTPD · ProFTPD
ProFTPD Improper Access Control Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2015-5477
ISC · BIND
ISC BIND Data Processing Errors Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2016-3081
Apache · Struts
Apache Struts Command Injection Vulnerability
■Detected Oct 8 · 3-day patch deadline

KEV Intelligence Brief: Update — Citrix NetScaler

Audience: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR Reporting Period: October 9, 2026

CISA quietly revised its NetScaler alert late Friday afternoon, and one change rewrites the risk picture we published on October 8. CVE-2026-88779 is not just a denial-of-service bug. CISA now says attackers can use it to force an unpatched appliance to reboot, which can trigger code they planted earlier through CVE-2026-88771. The alert also folds in a tenth NetScaler CVE, CVE-2026-107406, and moves CISA's guidance firmly toward a compromise-first posture: preserve evidence, restore from a clean backup, rotate everything. If your NetScaler plan was "patch this weekend," it needs another look.

Correction: CVE-2026-88779 Is Part of the RCE Chain

Our October 8 brief described CVE-2026-88779 as a denial-of-service flaw with lower immediate impact than the two RCE bugs. CISA's update shows that framing was incomplete.

On deployments configured as a SAML Service Provider or Identity Provider, CVE-2026-88779 can independently knock the appliance offline. On unpatched deployments, it can also serve as the trigger in a two-step attack: an attacker injects code through CVE-2026-88771, then uses CVE-2026-88779 to force a reboot that executes it. In practice, that means an appliance compromised through CVE-2026-88771 may be sitting on staged code that has not run yet, and a crash is the signal that it just did.

Operational guidance: Treat any unexplained NetScaler reboot or crash since late September as a potential execution event, not a stability issue. Pull the timestamps, correlate them with authentication and HTTP logs, and escalate rather than closing the ticket. Any appliance configured for SAML SP or IdP roles moves to the top of the patch queue.

Ten CVEs, Three Exploited: What Changed in the Alert

Citrix has now disclosed ten vulnerabilities across NetScaler ADC and Gateway: CVE-2026-88771 through CVE-2026-88779, plus CVE-2026-107406. Three are in the KEV catalog: CVE-2026-88771 and CVE-2026-88772 (added September 27) and CVE-2026-88779 (added October 4). CISA has not added CVE-2026-107406 or CVE-2026-88773 through CVE-2026-88778 to KEV, and public technical detail on CVE-2026-107406 remains thin. CISA is nonetheless urging patching across the full range, and that is the right call: on an appliance family this heavily targeted, the gap between "disclosed" and "exploited" has been measured in hours.

That speed is documented. eSentire tracked at least four separate clusters exploiting CVE-2026-88771, including one active before public disclosure and others hitting customers within roughly a day of proof-of-concept code going public. Mandiant and Google Threat Intelligence report dozens of organizations hit through CVE-2026-88772, with the WHIPSHOT web shell and a Python tunneler called SLAPSHOT. The pre-disclosure activity matters for one reason above all: your compromise window may start earlier than September 27.

Operational guidance: Confirm every appliance is on a build that addresses all ten CVEs, not just the three in KEV. Citrix's bulletin lists 14.1-73.37 and 13.1-64.23 (with FIPS and NDcPP equivalents) as fixed builds for CVE-2026-88771; verify against the current bulletin that those builds also cover CVE-2026-107406 before marking an appliance done.

Investigate Before You Patch

CISA's update makes the sequence explicit, and it is the reverse of most teams' instinct. Patching can reduce forensic visibility, so check for compromise first.

Preserve evidence. NetScaler's local logs rotate quickly and can overwrite artifacts. Forward logs to a SIEM or central log store now, and capture forensic images of suspected appliances before applying updates. Citrix has published indicators through NetScaler Console, and CISA has released a SIGMA detection rule resource.

Hunt for known post-exploitation artifacts. Researchers at LevelBlue and eSentire have published consistent indicators from active campaigns:

  • Authentication events with attacker-controlled usernames containing variations of pitboss or NSPPE
  • A local account named sec_monitor with the superuser role added to /flash/nsconfig/ns.conf
  • A PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, with /etc/httpd.conf modified to enable PHP and map the shell to URLs that mimic NetScaler CSS files
  • Web shells disguised as .deb files under /var/netscaler/gui/vpn/scripts/linux/
  • /bin/sh with permissions changed to 6555
  • Configuration archives staged at /tmp/update_result_*.tgz (the script deletes these after upload, so their absence proves nothing)
  • Outbound connections to 64.94.85[.]67, 31.56.197[.]72, 23.27.143[.]20, or 45.141.21[.]130

If compromise is suspected, restore rather than clean. CISA recommends restoring a known-good backup that predates any confirmed or suspected compromise, then rotating every restored secret: local account passwords, key-encryption keys, and SSL certificates. Given the pre-disclosure exploitation, "predates compromise" may mean reaching back further than your newest backup. Then patch, and follow Citrix's guidance for suspected NetScaler ADC compromise.

Operational guidance: For federal agencies and contractors, an appliance that was exposed and unpatched during the exploitation window should be documented as a compromise assessment under BOD 26-04, not closed as a late patch. Hold the backup restore until evidence is preserved, and treat certificate rotation as mandatory even when no indicators turn up.

Summary Deadline Status

| CVE | Product | KEV Added | Deadline | Status | |---|---|---|---|---| | CVE-2026-88771 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88772 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88779 | NetScaler ADC / Gateway | Oct 4 | Oct 7 | Overdue | | CVE-2026-88773 – 88778 | NetScaler ADC / Gateway | Not in KEV | — | Patch now | | CVE-2026-107406 | NetScaler ADC / Gateway | Not in KEV | — | Patch now |

All three KEV-listed NetScaler CVEs are past their BOD 26-04 deadlines. The other seven carry no federal deadline yet, but CISA's alert and the exploitation tempo around this product family give organizations every reason not to wait for one.

Sources: CISA Alert: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway · CISA KEV Catalog · Citrix Security Bulletin CTX697096 · LevelBlue: CVE-2026-88771 Exploitation Artifacts and Hunt Indicators · eSentire: Tracking NetScaler Exploitation · The Hacker News: NetScaler Post-Exploitation Payload

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 10, 2026

FBI Arrests ShinyHunters Member, Seizes Additional Chinese Hacking Infrastructure

The FBI arrested a suspect linked to ShinyHunters, the threat group that claimed responsibility for breaching the FBI's jobs portal last month. The arrest is part of an ongoing global investigation targeting ShinyHunters members. Separately, the Department of Justice announced seizure of additional scanning and phishing tools used by Chinese government-associated hackers to conduct cyber operations against critical infrastructure. The action follows yesterday's disruption of Flax Typhoon infrastructure and represents continued law enforcement focus on Chinese state-sponsored threat actors targeting U.S. systems.

Canadian Cybersecurity Executive Charged in Federal Hacking Case

Edward Dubrovsky, a Canadian cybersecurity executive who recently published a book on handling cyber extortion, has been charged with conspiracy in a federal hacking and data extortion case. The charges represent an unusual case of an alleged insider threat from within the cybersecurity industry. Details on the specific conspiracy and victims remain limited at this time.

P7 DarkSword Spyware Variant Targets Vulnerable iOS Devices

A new sophisticated variant of DarkSword spyware has emerged targeting iPhone users running outdated iOS versions. The malware enables remote command execution and exfiltration of sensitive data from compromised devices. The campaign highlights continued exploitation of users who fail to apply available iOS security updates.

Sources: Los Angeles Times · The Hill · Politico · Shift Delete

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comOct 8

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Hackers tied to Chinese cybersecurity company Integrity Technology Group stole emails from government organizations, law enforcement agencies, and hea...

https://www.cisa.govOct 8

CISA, FBI, NSA and International Partners Warn of China-based Cybersecurity Company Enabling Threat Actors

CISA, FBI, NSA, and international partners issued a joint advisory warning that Integrity Technology Group is enabling Chinese threat actors to target...

https://securityweek.comOct 8

US Disrupts Chinese State-Sponsored Hacking Tools

The United States announced the disruption of two hacking tools—MicroScan for vulnerability scanning and FishHub for spear phishing—used by Chinese st...

https://thehackernews.comOct 8

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

The FBI and Department of Justice announced the disruption of malicious tools used by Chinese APT group Flax Typhoon, seizing several domains used to ...

https://cybernews.comOct 5

Massive KVM Zero-Day Enables VM Escape to Host Root on Cloud Hypervisor

A critical KVM zero-day vulnerability discovered by researcher Paulos Yibelo enables attackers to escape a guest virtual machine and gain root-level a...

https://www.reuters.comOct 11

Canadian ransomware negotiator arrested amid FBI hacker crackdown - Reuters

A person ​briefed on the matter said the person was Canadian cybersecurity executive Edward Dubrovsky. Federal ​prosecutors in Philadelphia did ...

https://securityaffairs.comOct 8

US Disrupts China-Linked Integrity Tech's Cyber Espionage Tools

The Justice Department and FBI seized hacking tools Microscan and FishHub built and operated by Beijing-based Integrity Technology Group to scan and h...

https://thehackernews.comOct 10

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be .....


Updated daily