CISA Issues Urgent Deadlines for Citrix and SharePoint Vulnerabilities
Article Content
- •CISA has issued a 3-day deadline for patching critical vulnerabilities.
- •CVE-2026-65660 for SharePoint is under active exploitation.
- •Citrix NetScaler vulnerabilities are also being actively exploited.
CISA has set a 3-day deadline for organizations to address critical vulnerabilities in Citrix NetScaler and SharePoint. The Citrix NetScaler zero-day vulnerabilities are under active exploitation, while SharePoint CVE-2026-65660 was added to the CISA KEV list on September 25, 2026, indicating active exploitation. CVE-2026-65660 was published on August 11, 2026, and a proof-of-concept (PoC) was released on the same day it was added to the KEV list. Organizations using Citrix NetScaler and SharePoint are urged to implement patches immediately to mitigate risks. The vulnerabilities could lead to unauthorized access and data breaches if not addressed promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-65660 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…