{"total":10,"items":[{"id":359,"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","original_title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","source_rating":null,"summary":"Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","type":"research","language":"en","published_at":"2026-09-30T20:00:04+00:00","severity":"middel","priority":37,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69413,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63393,"in_kev":true,"kev_ransomware":false}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":28,"title":"Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu","original_title":"Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu","source_rating":null,"summary":"Er is een aantal kwetsbaarheden gevonden in Citrix NetScaler ADC en NetScaler Gateway. De ernst van deze kwetsbaarheden varieert, met CVSS-scores tot 9,5. De kwetsbaarheden betreffen verschillende beveiligingsproblemen die onder meer kunnen leiden tot het omzeilen van beveiligingsmaatregelen, het onbruikbaar maken van ","ai":false,"actions":[],"url":"https://www.ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu","type":"news","language":"nl","published_at":"2026-09-30T14:55:00+00:00","severity":"laag","priority":20,"vendors":["Citrix"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ncsc-nl-nieuws","name":"NCSC-NL Nieuws & alerts","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":416,"title":"Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway","original_title":"Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway","source_rating":null,"summary":"Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar:\n\n- Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37\n- Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóó","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0394","type":"advisory","language":"nl","published_at":"2026-09-30T08:38:43+00:00","severity":"kritiek","priority":95,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69413,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63393,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88775","cvss":8.8,"epss":0.00384,"epss_percentile":0.30016,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-88776","cvss":8.8,"epss":0.00384,"epss_percentile":0.30015,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-88777","cvss":8.8,"epss":0.00384,"epss_percentile":0.30015,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-88778","cvss":8.8,"epss":0.00379,"epss_percentile":0.29442,"in_kev":false,"kev_ransomware":false}],"cve_count":8,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":{"kans":"H","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":506,"title":"Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway","original_title":"Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway","source_rating":null,"summary":"The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.","ai":false,"actions":[],"url":"https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway","type":"news","language":"en","published_at":"2026-09-28T12:00:00+00:00","severity":"laag","priority":0,"vendors":["Citrix"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ncsc-uk","name":"NCSC-UK News","category":"overheid","country":"UK","license":"© Crown copyright","reuse":"excerpt"},"bundle":null},{"id":81,"title":"Warning: Citrix NetScaler ADC & NetScaler Gateway RCE Vulnerabilities Actively Exploited as Zero-Days, Patch Immediately!","original_title":"Warning: Citrix NetScaler ADC & NetScaler Gateway RCE Vulnerabilities Actively Exploited as Zero-Days, Patch Immediately!","source_rating":null,"summary":"","ai":false,"actions":[],"url":"https://ccb.belgium.be/advisories/warning-citrix-netscaler-adc-netscaler-gateway-rce-vulnerabilities-actively-exploited","type":"advisory","language":"en","published_at":"2026-09-28T08:53:55+00:00","severity":"middel","priority":35,"vendors":["Citrix"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ccb-be","name":"CCB / Safeonweb@work (België)","category":"overheid","country":"BE","license":"© CCB, hergebruik voorbehouden","reuse":"link"},"bundle":null},{"id":86,"title":"2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway","original_title":"2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway","source_rating":null,"summary":"On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabi","ai":false,"actions":[],"url":"https://cert.europa.eu/publications/security-advisories/2026-014/","type":"advisory","language":"en","published_at":"2026-09-27T19:40:52+00:00","severity":"laag","priority":15,"vendors":["Citrix"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"cert-eu","name":"CERT-EU Security Advisories","category":"overheid","country":"EU","license":"CC BY 4.0, samengevat en vertaald door Seinwacht","reuse":"open"},"bundle":null},{"id":136,"title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","original_title":"CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","source_rating":null,"summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88772","type":"kev","language":"en","published_at":"2026-09-27T00:00:00+00:00","severity":"hoog","priority":65,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69413,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":137,"title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","original_title":"CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability","source_rating":null,"summary":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88771","type":"kev","language":"en","published_at":"2026-09-27T00:00:00+00:00","severity":"hoog","priority":65,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63393,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01063,"source_count":3,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":161,"title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","original_title":"CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","source_rating":null,"summary":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass aut","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19490","type":"kev","language":"en","published_at":"2026-09-09T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-19490","cvss":9.3,"epss":0.0797,"epss_percentile":0.94579,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.3,"epss_max":0.0797,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":90,"title":"2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway","original_title":"2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway","source_rating":null,"summary":"On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).\n\nCERT-EU recommends updating affected devices as soon as possible.","ai":false,"actions":[],"url":"https://cert.europa.eu/publications/security-advisories/2026-010/","type":"advisory","language":"en","published_at":"2026-08-19T18:13:47+00:00","severity":"laag","priority":15,"vendors":["Citrix"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"cert-eu","name":"CERT-EU Security Advisories","category":"overheid","country":"EU","license":"CC BY 4.0, samengevat en vertaald door Seinwacht","reuse":"open"},"bundle":null}]}