CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has set September 30 as the deadline for federal agencies to patch two actively exploited zero-day vulnerabilities in Citrix NetScaler products. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, permit unauthenticated remote code execution under typical deployment conditions and target perimeter devices such as remote access gateways and application publishing services.
CVE-2026-88771 is particularly severe because it allows remote code execution without authentication on NetScaler ADC and NetScaler Gateway using default settings. No additional requirements or credentials are needed, leaving unpatched systems fully exposed to attackers. CVE-2026-88772 can result in either remote code execution or denial of service through a memory overflow triggered when DTLS is enabled on VPN vServers, a configuration that is active by default in many deployments.
Citrix has published updates for the 14.1 and 13.1 branches, including FIPS and NDcPP certified builds. Administrators must apply at minimum version 14.1-73.37 or 13.1-64.23 (or their certified equivalents). Deployments of Secure Private Access Hybrid that rely on NetScaler instances inherit the same risk and require the same remediation.
The security bulletin also addresses six additional vulnerabilities ranging from CVE-2026-88773 to CVE-2026-88778. These include HTTP request smuggling, policy bypass issues, and techniques related to TCP ISN prediction. For the TCP ISN case, Citrix provides a recommended configuration change to mitigate specific scenarios when the affected functionality is in use.
CISA advises organizations to look for signs of compromise before applying patches when feasible and to preserve forensic evidence if compromise is suspected. In environments with limited telemetry, reviewing logs in NetScaler Console and engaging specialized forensic analysis can help distinguish between simply closing the vulnerability and leaving a latent intrusion undetected.
Non-federal organizations should follow the same urgency: first inventory all NetScaler instances, prioritize those exposed to the internet, verify DTLS status on VPN vServers, and schedule maintenance windows with rollback plans. NetScaler 12.1 and 13.0 are no longer supported and will not receive patches, making immediate migration to supported branches the only viable option.
Related articles
CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites
A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.
Mandiant Uncovers WAF Bypass Campaign Exploiting Critical Oracle PeopleSoft CVE-2026-35273
Mandiant has identified an active campaign abusing CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub (PSEMHUB). Attackers bypass web application firewalls by replacing the literal path /PSEMHUB/ with /%50SEMHUB/, exploiting the fact that many WAF rules inspect the URL before decoding while the PeopleSoft application server decodes it afterward. The exploitation chain relies on Java object deserialization via POST requests to /%50SEMHUB/hub, allowing deployment of two distinct JSP web shells. The group then establishes persistence with a trojanized installer that drops the SIDEEYE backdoor along with Neo-reGeorg and MeshAgent. Activity attributed to UNC6240, linked to ShinyHunters, began as a zero-day against educational institutions in June 2026 and has since expanded to higher education, technology, healthcare, agriculture, transportation, and government sectors.
Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic
A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.
Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited
Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.