ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Sunday, 27 September 2026: Citrix NetScaler zero-days under active exploitation top a heavy day for defenders

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

Citrix NetScaler zero-days under active exploitation top a heavy day for defenders

Good morning. CISA said it is amplifying Citrix's disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 and CVE-2026-88778. In a separate alert CISA added two of them to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation: CVE-2026-88771, which CISA describes as an improper input validation vulnerability, and CVE-2026-88772, which CISA describes as an improper restriction of operations within the bounds of a memory buffer.

The Hacker News reported that security firm watchTowr said on September 26 that two unpatched NetScaler zero-days allowing remote code execution are being actively exploited in the wild, and that Citrix has not confirmed the flaws or published a fix. BleepingComputer reported that Citrix administrators are being warned to shut down NetScalers over the two exploited zero-days, with patches expected next week. If you run NetScaler ADC or Gateway, match your appliances against the CVEs above; BleepingComputer's guidance to take appliances offline until a fix ships is the mitigation on record while no patch exists.

SecurityWeek reported that CISA added Microsoft SharePoint flaw CVE-2026-65660 to its KEV catalogue, now exploited in attacks, with a federal patching deadline of September 28. Treat that deadline as the clock for SharePoint operators.

Read the full briefing →

Zoom out: Three separately exploited flaws — in Citrix NetScaler, Microsoft SharePoint and Oracle PeopleSoft — were being acted on at the same time.

Elsewhere

  • The Register: Certainties in life: Death, taxes, and critical Citrix vulns under attack Read it
  • Help Net Security: If you do one security check this quarter, make it agent memory Read it
  • BleepingComputer: CISA orders feds to patch exploited Citrix flaws by Wednesday Read it
  • Help Net Security: Authorizer: Open-source authentication and authorization for your apps Read it
  • The Register: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought Read it
  • Help Net Security: AI tests the limits of enterprise security governance Read it
  • Help Net Security: Product showcase: A photo can fool your eyes. Verdict checks the evidence Read it
  • Help Net Security: Quantum random numbers can pass the tests and still leak clues to attackers Read it
  • BleepingComputer: OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email Read it
  • CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway Read it
  • CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
  • BleepingComputer: Citrix admins warned to shut down NetScalers over 2 exploited zero-days Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email