Citrix bulletin CTX697096 (Sunday Sep 27) fixes eight NetScaler ADC and Gateway flaws, CVE-2026-88771 through -88778, and says exploits of the first two “on unmitigated NetScaler deployments have been observed.” CVE-2026-88771 (CVSS 4.0 score 9.5) lets an unauthenticated attacker execute arbitrary commands on all NetScaler ADC and Gateway deployments, including the default configuration. CVE-2026-88772 (CVSS 4.0 score 9.5) is a memory overflow leading to code execution or denial of service when DTLS is enabled, which is on by default for VPN vServers. Fixed builds: 14.1-73.37 (also 14.1 FIPS), 13.1-64.23, and 13.1-37.279 (13.1-FIPS/NDcPP). Secure Private Access hybrid deployments using NetScaler are also affected; Citrix is upgrading its managed cloud services itself. Both flaws were exploited as zero-days before patches were available, and watchTowr publicly warned of exploitation on Sep 26. CISA added both to KEV on Sep 27 (federal deadline Wednesday Sep 30), citing “reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” and urged organizations to preserve forensic evidence before patching. No attacker has been named publicly, and CISA lists ransomware use as unknown. watchTowr notes that appliances patched for the earlier CVE-2026-19490 are still exposed. Shadowserver tracks more than 23,000 IPs with NetScaler fingerprints; that counts exposed devices, not vulnerable ones.
Separately, Kiteworks (formerly Accellion) lifted a precautionary shutdown advisory on Sep 27. On Sep 25 it cited “credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” recommended a nine-hour weekend shutdown of self-managed systems, and took its hosted systems down itself. Hosted systems are back up, and customers with self-hosted Advanced Forms are told to contact support. According to an email to customers, per SecurityWeek, a severe Advanced Forms vulnerability triggered the shutdown; the email says the product is enabled for “fewer than 1% of our customers, under 50 organizations” and that Kiteworks is working with partners including Mandiant. Kiteworks says it has no indication of compromise and that version 9.5.1 addresses all known vulnerabilities. There is no public CVE and no evidence of exploitation.
Livermore takeaway: treat every internet-facing NetScaler as a possible incident, not just a patch job. Before upgrading, capture logs, a support bundle, and a core dump (NCSC-NL says keep the memory dump and at least a month of logs), then run Citrix’s IoC scan in NetScaler Console. A clean scan is not proof: Citrix says its IoCs “might fail to identify actual compromises.” On 13.1, watchTowr says use 13.1-64.24 if show ns variable returns variables, to avoid a reboot loop; CVE-2026-88778 also needs the Enhanced ISN Generation config change. Afterward, rotate credentials, secrets, and certificates used by or stored on the appliance, and keep management interfaces off the internet. NetScaler 12.1 and 13.0 are end of life with no fix, so migrate them. For Kiteworks, confirm 9.5.1 and whether Advanced Forms is enabled; if it is, follow support’s guidance before re-exposing it. Both stories share a lesson: know which edge and file-transfer appliances face the internet, who can pull the plug on a weekend, and what evidence you’ll keep.