Threat Brief — 2026-09-27 — Citrix NetScaler zero-days hit CISA KEV
CISA has formally added two actively exploited Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog, escalating an already-critical situation first reported earlier today. The advisory also reveals that Citrix has disclosed a total of eight new vulnerabilities affecting NetScaler ADC and Gateway—not just the two initially reported. Organizations running these products face immediate risk of remote code execution with confirmed in-the-wild exploitation.
Top items
- Citrix NetScaler ADC/Gateway — eight CVEs disclosed, two in CISA KEV with active exploitation. CISA amplified Citrix's disclosure of eight new vulnerabilities affecting NetScaler ADC and Gateway. Two of these—CVE-2026-88771KEV (improper input validation) and CVE-2026-88772KEV—have been added to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation in the wild. This is a development of the story first reported 2026-09-27 by The Hacker News covering two unpatched NetScaler RCE zero-days; the new developments are CISA's formal KEV listing and the expanded scope to eight total CVEs. (src: CISA Current Activity) (src: CISA KEV Catalog) (first reported: The Hacker News)
Themes
KEV velocity. CISA moved these NetScaler CVEs into the KEV catalog on the same day the initial disclosure circulated—compressing the window between advisory and formal exploitation confirmation to hours rather than days. This pattern has repeated across several recent stories (Cisco FMC, SharePoint, Adobe Commerce) and signals that threat actors are weaponising critical infrastructure CVEs faster than in prior years.
