Skip to content
Timeline and KEV deadline

Timeline and KEV deadline

cybermerge.com • October 2, 2026

Citrix published CTX697096 on Sunday, September 27, 2026 for eight NetScaler ADC / Gateway flaws. Confirmed in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772 ( CVSS 9.5 each): unauthenticated RCE on default configs, and RCE-or-DoS when DTLS is on (default on VPN vServers). CISA added both to KEV the same day; FCEB BOD deadline September 30 . Pre-patch weekend: NCSC-NL private warnings and admins told to shut appliances ( Sat Sep 26 ). Shadowserver : ~ 23k internet-exposed NetScaler fingerprints — not a confirmed vulnerable count.

Edge appliance, unauth RCE, vendor-confirmed exploitation, federal clock already running. That is the Monday lead.

Primary: Citrix security bulletin CTX697096 (initial publication 2026-09-27 ). Table of eight CVEs; the two with observed exploits:

CVE-2026-88771 — improper input validation (CWE-20) → unauthenticated arbitrary command execution. Pre-condition: all NetScaler ADC and Gateway deployments, including default configuration; no extra feature required. CVSS v4 base 9.5 .

CVE-2026-88772 — memory overflow (CWE-119) → remote code execution or denial of service. Pre-condition: DTLS enabled on ADC/Gateway; Citrix notes DTLS is enabled by default on VPN virtual servers . CVSS v4 base 9.5 .

Citrix wording on exploitation: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.” Cloud Software Group “strongly urges” affected customers to install updated builds ASAP. Fixed builds cited in the bulletin: 14.1-73.37+ , 13.1-64.23+ , 14.1-FIPS 14.1-73.37 FIPS+ , 13.1-FIPS / 13.1-NDcPP 13.1.37.279+ . Affected: those branches before those builds. Secure Private Access Hybrid NetScaler instances also need the recommended builds. Bulletin scope: customer-managed ADC/Gateway; Citrix-managed cloud / Adaptive Authentication is handled by Cloud SG. Victim census / actor attribution: Undisclosed .

The other six in the same bulletin (not the KEV pair): CVE-2026-88773 HTTP request smuggling (9.3); CVE-2026-88774 feature policy bypass (7.0); CVE-2026-88775 / 88776 / 88777 memory-overflow DoS / erratic behavior paths (8.8 each, config-gated); CVE-2026-88778 TCP ISN prediction (8.8) — mitigated via enhanced ISN generation TCP config change per NetScaler docs, not only a build bump. No ITW claims for those six; Citrix’s observed-exploit sentence names 88771 and 88772 only.

CISA same day (Sep 27): alert amplifying the eight CVEs and confirming active exploitation of the two critical zero-days “globally”; separate KEV notice adding CVE-2026-88771 (improper input validation) and CVE-2026-88772 (improper restriction of operations within the bounds of a memory buffer). Per BOD 26-04 , FCEB agencies must remediate KEV entries on publicly exposed assets that grant total control post-exploitation — secondary reporting (BleepingComputer Sep 28) puts the Citrix deadline at September 30 . CISA also: check for IoC before patching when possible; preserve forensics if compromise is suspected (updates can wipe visibility). Citrix ships “generic” IoCs via NetScaler Console and has published compromise-assessment guidance — vendor itself warns those IoCs “might be of limited forensic value.”

Pre-disclosure weekend (secondary, consistent across SecurityWeek / BC): starting Saturday, September 26 , NetScaler admins reported IT suppliers, CERT/MDR, and national agencies telling them to shut appliances immediately , often without public detail. Thread material traced to a private NCSC-NL pre-notification (reportedly TLP:AMBER) describing two critical NetScaler zero-days without CVE IDs, exploitation identified at multiple Citrix customers worldwide, and Citrix discovering issues while investigating customer incidents. NCSC-NL declined to confirm the circulated notice to non-constituency press. watchTowr publicly flagged credible rumors of multiple unpatched NetScaler RCEs before the bulletin landed. /TLP copies are not primary; Citrix + CISA are the sources for the confirmed CVEs and ITW.

Exposure vs vulnerability: Shadowserver tracks roughly 23,000 IP addresses with NetScaler fingerprints on the public internet (BC breakdown: nearly ~22k ADC fingerprints and just over ~1.5k Gateway). That is an internet-exposed fingerprint count , not a confirmed vulnerable-install census — honeypots, already-patched boxes, and non-vulnerable configs are not separated in that figure. Successful-compromise count: Undisclosed .

Update Sep 29: CERT-EU published a root-cause write-up (Mon Sep 28, 19:30 CEST) for CVE-2026-88771 : a log-injection path. Attackers stuff base64 bash payloads into HTTP User-Agent strings, then hammer authentication logs with a crafted username containing the string PPE missed too many heartbeats ; when NetScaler’s ns_monuploadd_err.pl script greps the logs for that line, the value is interpolated unquoted into a shell command and executed. Observed post-compromise: /etc/httpd.conf modified to enable PHP, then a web shell dropped in an internet-reachable path. CERT-EU credits colleagues at the European Court of Auditors and European Central Bank for spotting the attacker IPs in NetScaler logs (CERT-EU does not state either was compromised). Hunt: auth logs for that heartbeat string, base64 in User-Agent fields, httpd.conf integrity — then patch. With the mechanism now public, expect faster weaponization ahead of the Sep 30 FCEB deadline.

Update Sep 29 evening — Mandiant / GTIG primary: Google Cloud blog Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29). Mandiant Consulting + GTIG: active ITW on CVE-2026-88772 since at least early September ; sectors observed as likely impacted: North America and Europe — government, financial services, technology, education, legal and professional services. Exact victim census: Undisclosed in the blog (CyberScoop quotes Mandiant Consulting CTO Charles Carmakal: “dozens of impacted organizations”; post attributes to “advanced and suspected state- threat actors”; those phrases are Carmakal/CyberScoop’s, not a CyberMerge count). Post-exploitation toolkit newly named: WHIPSHOT (PHP web shell; Base64 C2 in HTTP headers; can launch companion) and SLAPSHOT (Python TCP tunneler into internal nets for recon/credential theft). Persistence patterns: httpd.conf handlers for .deb / .sig , icon AliasMatch under /vpn/media/ , setuid on /bin/sh , artifacts /tmp/.uxdport and /tmp/.uxdlock . Mandiant notes Citrix also disclosed ITW on CVE-2026-88771 ; DTLS/UDP-443 mitigations address 88772 only — fixed builds required for both. GreyNoise (via BC): 88771 exploit attempt observed Sep 24 from 149.104.78.141. FCEB BOD deadline remains September 30 — hunt before you overwrite forensics if you can.

POV: Patch CTX697096 builds now; treat internet-facing ADC/Gateway as KEV-urgent through Sep 30 for FCEB and as board-urgent for everyone else. Hunt/IoC via NetScaler Console before you overwrite disks if you can. Shadowserver’s ~23k exposed fingerprints do not equal “23k vulnerable.” Sources: CTX697096 + CISA Sep 27 alerts; the pre-patch shutdown timeline is per BC / SecurityWeek / watchTowr.

Citrix CTX697096 — NetScaler ADC/Gateway Security Bulletin CVE-2026-88771 through CVE-2026-88778 — Sep 27, 2026

CISA Alert: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — Sep 27, 2026

CISA: Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-88771, CVE-2026-88772) — Sep 27, 2026

BleepingComputer: CISA orders feds to patch exploited Citrix flaws by Wednesday — Sep 28, 2026

SecurityWeek: Citrix confirms 2 NetScaler zero-days after admins pulled the plug — Sep 28, 2026

BleepingComputer: Citrix confirms two NetScaler RCE zero-days exploited — Sep 27, 2026

watchTowr: Citrix NetScaler zero-day vulnerabilities FAQ

CERT-EU: Taking ‘execute logging’ a bit too literally — CVE-2026-88771 — Sep 28, 2026

Mandiant / GTIG (Google Cloud): Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances — Sep 29, 2026

BleepingComputer: Hackers exploit Citrix NetScaler zero-day to deploy web shells — Sep 29, 2026 (2:37 PM)

CyberScoop: Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected — Sep 29, 2026