CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief: Update — Citrix NetScaler
Audience: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR Reporting Period: October 9, 2026
CISA quietly revised its NetScaler alert late Friday afternoon, and one change rewrites the risk picture we published on October 8. CVE-2026-88779 is not just a denial-of-service bug. CISA now says attackers can use it to force an unpatched appliance to reboot, which can trigger code they planted earlier through CVE-2026-88771. The alert also folds in a tenth NetScaler CVE, CVE-2026-107406, and moves CISA's guidance firmly toward a compromise-first posture: preserve evidence, restore from a clean backup, rotate everything. If your NetScaler plan was "patch this weekend," it needs another look.
Correction: CVE-2026-88779 Is Part of the RCE Chain
Our October 8 brief described CVE-2026-88779 as a denial-of-service flaw with lower immediate impact than the two RCE bugs. CISA's update shows that framing was incomplete.
On deployments configured as a SAML Service Provider or Identity Provider, CVE-2026-88779 can independently knock the appliance offline. On unpatched deployments, it can also serve as the trigger in a two-step attack: an attacker injects code through CVE-2026-88771, then uses CVE-2026-88779 to force a reboot that executes it. In practice, that means an appliance compromised through CVE-2026-88771 may be sitting on staged code that has not run yet, and a crash is the signal that it just did.
Operational guidance: Treat any unexplained NetScaler reboot or crash since late September as a potential execution event, not a stability issue. Pull the timestamps, correlate them with authentication and HTTP logs, and escalate rather than closing the ticket. Any appliance configured for SAML SP or IdP roles moves to the top of the patch queue.
Ten CVEs, Three Exploited: What Changed in the Alert
Citrix has now disclosed ten vulnerabilities across NetScaler ADC and Gateway: CVE-2026-88771 through CVE-2026-88779, plus CVE-2026-107406. Three are in the KEV catalog: CVE-2026-88771 and CVE-2026-88772 (added September 27) and CVE-2026-88779 (added October 4). CISA has not added CVE-2026-107406 or CVE-2026-88773 through CVE-2026-88778 to KEV, and public technical detail on CVE-2026-107406 remains thin. CISA is nonetheless urging patching across the full range, and that is the right call: on an appliance family this heavily targeted, the gap between "disclosed" and "exploited" has been measured in hours.
That speed is documented. eSentire tracked at least four separate clusters exploiting CVE-2026-88771, including one active before public disclosure and others hitting customers within roughly a day of proof-of-concept code going public. Mandiant and Google Threat Intelligence report dozens of organizations hit through CVE-2026-88772, with the WHIPSHOT web shell and a Python tunneler called SLAPSHOT. The pre-disclosure activity matters for one reason above all: your compromise window may start earlier than September 27.
Operational guidance: Confirm every appliance is on a build that addresses all ten CVEs, not just the three in KEV. Citrix's bulletin lists 14.1-73.37 and 13.1-64.23 (with FIPS and NDcPP equivalents) as fixed builds for CVE-2026-88771; verify against the current bulletin that those builds also cover CVE-2026-107406 before marking an appliance done.
Investigate Before You Patch
CISA's update makes the sequence explicit, and it is the reverse of most teams' instinct. Patching can reduce forensic visibility, so check for compromise first.
Preserve evidence. NetScaler's local logs rotate quickly and can overwrite artifacts. Forward logs to a SIEM or central log store now, and capture forensic images of suspected appliances before applying updates. Citrix has published indicators through NetScaler Console, and CISA has released a SIGMA detection rule resource.
Hunt for known post-exploitation artifacts. Researchers at LevelBlue and eSentire have published consistent indicators from active campaigns:
- Authentication events with attacker-controlled usernames containing variations of
pitbossorNSPPE - A local account named
sec_monitorwith the superuser role added to/flash/nsconfig/ns.conf - A PHP web shell at
/var/netscaler/logon/LogonPoint/.local_journal, with/etc/httpd.confmodified to enable PHP and map the shell to URLs that mimic NetScaler CSS files - Web shells disguised as
.debfiles under/var/netscaler/gui/vpn/scripts/linux/ /bin/shwith permissions changed to 6555- Configuration archives staged at
/tmp/update_result_*.tgz(the script deletes these after upload, so their absence proves nothing) - Outbound connections to
64.94.85[.]67,31.56.197[.]72,23.27.143[.]20, or45.141.21[.]130
If compromise is suspected, restore rather than clean. CISA recommends restoring a known-good backup that predates any confirmed or suspected compromise, then rotating every restored secret: local account passwords, key-encryption keys, and SSL certificates. Given the pre-disclosure exploitation, "predates compromise" may mean reaching back further than your newest backup. Then patch, and follow Citrix's guidance for suspected NetScaler ADC compromise.
Operational guidance: For federal agencies and contractors, an appliance that was exposed and unpatched during the exploitation window should be documented as a compromise assessment under BOD 26-04, not closed as a late patch. Hold the backup restore until evidence is preserved, and treat certificate rotation as mandatory even when no indicators turn up.
Summary Deadline Status
| CVE | Product | KEV Added | Deadline | Status | |---|---|---|---|---| | CVE-2026-88771 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88772 | NetScaler ADC / Gateway | Sep 27 | Sep 30 | Overdue | | CVE-2026-88779 | NetScaler ADC / Gateway | Oct 4 | Oct 7 | Overdue | | CVE-2026-88773 – 88778 | NetScaler ADC / Gateway | Not in KEV | — | Patch now | | CVE-2026-107406 | NetScaler ADC / Gateway | Not in KEV | — | Patch now |
All three KEV-listed NetScaler CVEs are past their BOD 26-04 deadlines. The other seven carry no federal deadline yet, but CISA's alert and the exploitation tempo around this product family give organizations every reason not to wait for one.
Sources: CISA Alert: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway · CISA KEV Catalog · Citrix Security Bulletin CTX697096 · LevelBlue: CVE-2026-88771 Exploitation Artifacts and Hunt Indicators · eSentire: Tracking NetScaler Exploitation · The Hacker News: NetScaler Post-Exploitation Payload
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — October 10, 2026
FBI Arrests ShinyHunters Member, Seizes Additional Chinese Hacking Infrastructure
The FBI arrested a suspect linked to ShinyHunters, the threat group that claimed responsibility for breaching the FBI's jobs portal last month. The arrest is part of an ongoing global investigation targeting ShinyHunters members. Separately, the Department of Justice announced seizure of additional scanning and phishing tools used by Chinese government-associated hackers to conduct cyber operations against critical infrastructure. The action follows yesterday's disruption of Flax Typhoon infrastructure and represents continued law enforcement focus on Chinese state-sponsored threat actors targeting U.S. systems.
Canadian Cybersecurity Executive Charged in Federal Hacking Case
Edward Dubrovsky, a Canadian cybersecurity executive who recently published a book on handling cyber extortion, has been charged with conspiracy in a federal hacking and data extortion case. The charges represent an unusual case of an alleged insider threat from within the cybersecurity industry. Details on the specific conspiracy and victims remain limited at this time.
P7 DarkSword Spyware Variant Targets Vulnerable iOS Devices
A new sophisticated variant of DarkSword spyware has emerged targeting iPhone users running outdated iOS versions. The malware enables remote command execution and exfiltration of sensitive data from compromised devices. The campaign highlights continued exploitation of users who fail to apply available iOS security updates.
Sources: Los Angeles Times · The Hill · Politico · Shift Delete
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
US Disrupts China-Linked Integrity Tech's Cyber Espionage Tools
The Justice Department and FBI seized hacking tools Microscan and FishHub built and operated by Beijing-based Integrity Technology Group to scan and h...
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be .....
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities ...
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source ...
DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
The Justice Department and FBI seized Flax Typhoon-linked hacking tools Microscan and FishHub operated by Integrity Technology Group, accompanied by a...
Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers
Justice Department and FBI announced court-authorized seizures of Microscan and FishHub tools used by Flax Typhoon actors associated with Integrity Te...
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
The FBI and Justice Department seized Flax Typhoon hacking tools while FBI, CISA, NSA and international partners warned of Chinese government-linked a...
Chinese Government-Linked Cyber Threat Actors Combine Automated and Hands-On Hacking Tools
FBI, CISA, NSA, and NCSC-UK issue joint advisory on Chinese government-linked cyber threat actors combining automated scanning tools and hands-on expl...
Updated daily
