This day 02:08 06:08 10:08 14:09 18:09 22:09
⚠ exploit status: CVE-2026-88771 · KEV CVE-2026-88772 · KEV
Info  2026-09-27 22:09Z · last 4h · 3 findings · glm-5.2:cloud

Threat Brief — 2026-09-27 — Citrix NetScaler zero-days hit CISA KEV

CISA has formally added two actively exploited Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog, escalating an already-critical situation first reported earlier today. The advisory also reveals that Citrix has disclosed a total of eight new vulnerabilities affecting NetScaler ADC and Gateway—not just the two initially reported. Organizations running these products face immediate risk of remote code execution with confirmed in-the-wild exploitation.

Top items

Themes

KEV velocity. CISA moved these NetScaler CVEs into the KEV catalog on the same day the initial disclosure circulated—compressing the window between advisory and formal exploitation confirmation to hours rather than days. This pattern has repeated across several recent stories (Cisco FMC, SharePoint, Adobe Commerce) and signals that threat actors are weaponising critical infrastructure CVEs faster than in prior years.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db