This month: 9 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2015-3306
ProFTPD · ProFTPD
ProFTPD Improper Access Control Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2015-5477
ISC · BIND
ISC BIND Data Processing Errors Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2016-3081
Apache · Struts
Apache Struts Command Injection Vulnerability
■Detected Oct 8 · 3-day patch deadline

KEV Intelligence Brief: Update — Citrix NetScaler

Audience: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR Reporting Period: October 9, 2026

CISA quietly revised its NetScaler alert late Friday afternoon, and one change rewrites the risk picture we published on October 8. CVE-2026-88779 is not just a denial-of-service bug. CISA now says attackers can use it to force an unpatched appliance to reboot, which can trigger code they planted earlier through CVE-2026-88771. The alert also folds in a tenth NetScaler CVE, CVE-2026-107406, and moves CISA's guidance firmly toward a compromise-first posture: preserve evidence, restore from a clean backup, rotate everything. If your NetScaler plan was "patch this weekend," it needs another look.

Correction: CVE-2026-88779 Is Part of the RCE Chain

Our October 8 brief described CVE-2026-88779 as a denial-of-service flaw with lower immediate impact than the two RCE bugs. CISA's update shows that framing was incomplete.

On deployments configured as a SAML Service Provider or Identity Provider, CVE-2026-88779 can independently knock the appliance offline. On unpatched deployments, it can also serve as the trigger in a two-step attack: an attacker injects code through CVE-2026-88771, then uses CVE-2026-88779 to force a reboot that executes it. In practice, that means an appliance compromised through CVE-2026-88771 may be sitting on staged code that has not run yet, and a crash is the signal that it just did.

Operational guidance: Treat any unexplained NetScaler reboot or crash since late September as a potential execution event, not a stability issue. Pull the timestamps, correlate them with authentication and HTTP logs, and escalate rather than closing the ticket. Any appliance configured for SAML SP or IdP roles moves to the top of the patch queue.

Ten CVEs, Three Exploited: What Changed in the Alert

Citrix has now disclosed ten vulnerabilities across NetScaler ADC and Gateway: CVE-2026-88771 through CVE-2026-88779, plus CVE-2026-107406. Three are in the KEV catalog: CVE-2026-88771 and CVE-2026-88772 (added September 27) and CVE-2026-88779 (added October 4). CISA has not added CVE-2026-107406 or CVE-2026-88773 through CVE-2026-88778 to KEV, and public technical detail on CVE-2026-107406 remains thin. CISA is nonetheless urging patching across the full range, and that is the right call: on an appliance family this heavily targeted, the gap between "disclosed" and "exploited" has been measured in hours.

That speed is documented. eSentire tracked at least four separate clusters exploiting CVE-2026-88771, including one active before public disclosure and others hitting customers within roughly a day of proof-of-concept code going public. Mandiant and Google Threat Intelligence report dozens of organizations hit through CVE-2026-88772, with the WHIPSHOT web shell and a Python tunneler called SLAPSHOT. The pre-disclosure activity matters for one reason above all: your compromise window may start earlier than September 27.

Operational guidance: Confirm every appliance is on a build that addresses all ten CVEs, not just the three in KEV. Citrix's bulletin lists 14.1-73.37 and 13.1-64.23 (with FIPS and NDcPP equivalents) as fixed builds for CVE-2026-88771; verify against the current bulletin that those builds also cover CVE-2026-107406 before marking an appliance done.

Investigate Before You Patch

CISA's update makes the sequence explicit, and it is the reverse of most teams' instinct. Patching can reduce forensic visibility, so check for compromise first.

Preserve evidence. NetScaler's local logs rotate quickly and can overwrite artifacts. Forward logs to a SIEM or central log store now, and capture forensic images of suspected appliances before applying updates. Citrix has published indicators through NetScaler Console, and CISA has released a SIGMA detection rule resource.

Hunt for known post-exploitation artifacts. Researchers at LevelBlue and eSentire have published consistent indicators from active campaigns:

  • Authentication events with attacker-controlled usernames containing variations of pitboss or NSPPE
  • A local account named sec_monitor with the superuser role added to /flash/nsconfig/ns.conf
  • A PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal, with /etc/httpd.conf modified to enable PHP and map the shell to URLs that mimic NetScaler CSS files
  • Web shells disguised as .deb files under /var/netscaler/gui/vpn/scripts/linux/
  • /bin/sh with permissions changed to 6555
  • Configuration archives staged at /tmp/update_result_*.tgz (the script deletes these after upload, so their absence proves nothing)
  • Outbound connections to 64.94.85[.]67, 31.56.197[.]72, 23.27.143[.]20, or 45.141.21[.]130

If compromise is suspected, restore rather than clean. CISA recommends restoring a known-good backup that predates any confirmed or suspected compromise, then rotating every restored secret: local account passwords, key-encryption keys, and SSL certificates. Given the pre-disclosure exploitation, "predates compromise" may mean reaching back further than your newest backup. Then patch, and follow Citrix's guidance for suspected NetScaler ADC compromise.

Operational guidance: For federal agencies and contractors, an appliance that was exposed and unpatched during the exploitation window should be documented as a compromise assessment under BOD 26-04, not closed as a late patch. Hold the backup restore until evidence is preserved, and treat certificate rotation as mandatory even when no indicators turn up.

Summary Deadline Status

| CVE | Product | KEV Added | Deadline | Status | |---|---|---|---|---| | CVE-2026-88771 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88772 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88779 | NetScaler ADC / Gateway | Oct 4 | Oct 7 | Overdue | | CVE-2026-88773 – 88778 | NetScaler ADC / Gateway | Not in KEV | — | Patch now | | CVE-2026-107406 | NetScaler ADC / Gateway | Not in KEV | — | Patch now |

All three KEV-listed NetScaler CVEs are past their BOD 26-04 deadlines. The other seven carry no federal deadline yet, but CISA's alert and the exploitation tempo around this product family give organizations every reason not to wait for one.

Sources: CISA Alert: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway · CISA KEV Catalog · Citrix Security Bulletin CTX697096 · LevelBlue: CVE-2026-88771 Exploitation Artifacts and Hunt Indicators · eSentire: Tracking NetScaler Exploitation · The Hacker News: NetScaler Post-Exploitation Payload

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 9, 2026

FBI Disrupts Chinese State-Sponsored Infrastructure Targeting Critical Systems

The FBI seized seven internet domains operated by Chinese state-linked threat actor Flax Typhoon, disrupting two hacking tools—MicroScan and FishHub—used to breach U.S. critical infrastructure, power sector entities, and academic institutions. The domains were operated by China's Integrity Tech Group and used to conduct scanning operations and credential harvesting campaigns. Australian cyber authorities issued a coordinated advisory noting that Chinese government-linked actors are increasingly combining automated tooling with hands-on keyboard techniques to exfiltrate sensitive data from compromised networks. The disruption represents the latest U.S. government action targeting persistent Chinese infrastructure operations against high-value domestic targets.

Active Exploitation of AhsayCBS Backup Software and Ransomware Operations

Threat actors are actively chaining two unpatched vulnerabilities in AhsayCBS backup software to achieve unauthenticated remote code execution and deploy webshells, with at least five organizations confirmed compromised. Separately, Japan's IDCF Cloud suffered a ransomware attack on October 7 that caused a major outage at a data center cluster serving government clients in eastern Japan. A CloudSEK investigation identified a ransomware campaign affecting more than 24 organizations across six countries in which the operator used AI coding assistants for direct attack execution and data exfiltration. Additionally, a former MonsterCloud employee was charged with defrauding ransomware victims by obtaining decryption keys from threat actors then charging clients an $11 million markup for fake remediation services.

Discord Security Bot Breach Exposes 28 Million Accounts

The Discord security bot Double Counter disclosed that attackers compromised its cloud infrastructure for six hours, exposing data for 28 million Discord accounts and copying 12 GB of database records. The breach demonstrates the downstream impact when security tooling providers themselves become attack vectors. Separately, Japanese semiconductor testing firm Advantest confirmed that personal information was stolen during a February 2026 ransomware attack, adding to recent disclosures from legacy breach incidents.

Sources: Bleeping Computer · Yahoo Finance · Cyber.gov.au · SecurityWeek · Bleeping Computer · CyberSecurity News · SecurityWeek · Cybernews

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://securityaffairs.comOct 8

US Disrupts China-Linked Integrity Tech's Cyber Espionage Tools

The Justice Department and FBI seized hacking tools Microscan and FishHub built and operated by Beijing-based Integrity Technology Group to scan and h...

https://thehackernews.comOct 10

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be .....

https://thehackernews.comOct 10

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities ...

https://thehackernews.comOct 10

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source ...

https://cyberscoop.comOct 8

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The Justice Department and FBI seized Flax Typhoon-linked hacking tools Microscan and FishHub operated by Integrity Technology Group, accompanied by a...

https://www.justice.govOct 8

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

Justice Department and FBI announced court-authorized seizures of Microscan and FishHub tools used by Flax Typhoon actors associated with Integrity Te...

https://theregister.comOct 8

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

The FBI and Justice Department seized Flax Typhoon hacking tools while FBI, CISA, NSA and international partners warned of Chinese government-linked a...

https://www.ic3.govOct 8

Chinese Government-Linked Cyber Threat Actors Combine Automated and Hands-On Hacking Tools

FBI, CISA, NSA, and NCSC-UK issue joint advisory on Chinese government-linked cyber threat actors combining automated scanning tools and hands-on expl...


Updated daily