[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKXEVYqpuPLns6kjpXm0uZeBpV_KnliCJX7jhsXA5whk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"00985b03-3fa6-43b7-87b9-2b6f26a81386","citrix-netscaler-zero-days-exploited-globally-before-patches-released","1c2c1d83-2702-461e-8145-f539d902e78e","Citrix NetScaler Zero-Days Exploited Globally Before Patches Released","Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVSS 9.5) were actively exploited in the wild before official patches were available, forcing administrators to take appliances offline preemptively. CVE-2026-88771 allowed unauthenticated remote code execution across all NetScaler deployments, while CVE-2026-88772 targeted appliances with DTLS enabled — both representing high-value attack surfaces given NetScaler's role as a perimeter gateway. The fact that CISA added both CVEs to its Known Exploited Vulnerabilities catalog underscores how quickly threat actors weaponize flaws in widely deployed network infrastructure. Organizations without emergency patching procedures or compensating controls in place were left with no safe option other than taking critical systems offline, causing operational disruption.","**Immediate actions:**\n- Apply Citrix's emergency patches to all NetScaler ADC and Gateway appliances immediately upon release.\n- Disable DTLS on appliances where it is not operationally required to reduce the attack surface for CVE-2026-88772.\n- Check CISA's Known Exploited Vulnerabilities catalog daily and treat listed CVEs as priority remediation items.\n\n**Detection measures:**\n- Deploy network-level anomaly detection and WAF rules tuned to identify exploitation attempts against NetScaler management interfaces.\n- Review NetScaler logs for indicators of compromise (unexpected sessions, unusual RCE-related process spawning) dating back 30+ days.\n- Subscribe to vendor security advisories and relevant CERT feeds (e.g., NCSC-NL, CISA) to receive early TLP:AMBER pre-notifications.\n\n**Long-term improvements:**\n- Establish and rehearse a documented emergency patching procedure that allows critical patches to be deployed within 24–48 hours of disclosure.\n- Maintain a current, authoritative inventory of all internet-facing network appliances and their firmware\u002Fsoftware versions.\n- Implement network segmentation to isolate perimeter gateways so that a compromised appliance cannot pivot freely into internal systems.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","NIST IR-4: Incident Handling","CISA KEV Catalog Binding Operational Directive 22-01","ITIL Problem Management: Known Error and Workaround Documentation","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","published","2026-09-28T08:20:34.74052+00:00","2026-09-28T08:20:34.619+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.securityweek.com\u002Fcitrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug\u002F","citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug-8742de","Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[43],{"id":44,"date":45,"edition":46,"title":47,"audio_url":48},"b5e261b1-c8c1-44df-a81e-d952b51b2958","2026-09-28","afternoon","ThreatNoir Afternoon Brief — September 28","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-28\u002Fthreatnoir-afternoon-brief-2026-09-28.mp3"]