Asutorufaのブログ

こんにちは

Threat Intelligence

Threat Intelligence Daily · 2026-09-27

Two developments defined September 27: Citrix disclosed two NetScaler zero-days already exploited against unmitigated appliances, while Kiteworks lifted its precautionary shutdown recommendation and still reported no evidence of customer compromise.

1Critical0High1Medium0Low1Exploited2threats
2 CVEs
CVE-2026-88771CVE-2026-88772

Changes since yesterday

  • NEW — Citrix NetScaler:Citrix published CVE-2026-88771 and CVE-2026-88772 and confirmed exploitation against unmitigated NetScaler deployments.
  • UPDATED — Kiteworks:the vendor lifted its shutdown recommendation on September 27; hosted systems were restored and no compromise had been identified at that point.

Priority actions

  • Immediate:Upgrade NetScaler ADC/Gateway to 14.1-73.37, 13.1-64.23 or the applicable fixed FIPS/NDcPP build.
  • Immediate:Treat previously exposed NetScaler appliances as incident-response candidates. Patching removes the vulnerability but does not remove persistence established before the update.
  • Today:Kiteworks customers should follow the vendor’s restart guidance and retain telemetry from the precautionary shutdown window for later review.

Priority threats

NetScaler CVE-2026-88771 and CVE-2026-88772 exploited before disclosure

Severity
Critical
Status
Confirmed active exploitation / zero-day activity
CVSS
9.5 (v4) for both highlighted CVEs
CVE
CVE-2026-88771, CVE-2026-88772
Affected
Customer-managed NetScaler ADC and NetScaler Gateway

CVE-2026-88771 is an unauthenticated command-execution flaw caused by improper input validation and affects default deployments. CVE-2026-88772 is a memory-overflow issue that can produce RCE or DoS when DTLS is enabled; DTLS is enabled by default on VPN vServers. Citrix says exploits of both flaws have been observed on unmitigated systems.

Install the fixed releases and preserve appliance logs before cleanup. Review web roots, authentication paths and outbound connections for persistence or web-shell activity.

Sources (1)

Other notable items

Kiteworks lifted the precautionary shutdown recommendation

Severity
Medium
Status
Preventive response update; no compromise confirmed
Affected
Kiteworks systems covered by the September 25 advisory

Kiteworks updated its advisory on September 27 to say the shutdown recommendation was lifted for all customers and hosted systems were operating normally. The company still had not identified compromise.

Customers can restore systems under the vendor guidance while retaining logs from the threat window. The status change does not justify inventing a breach that the vendor did not report.

Sources (1)

Daily observations

  • The NetScaler disclosure is a patch-and-hunt case: confirmed pre-disclosure exploitation changes the task from preventive maintenance to compromise assessment.
  • Kiteworks moved in the opposite direction, from precautionary shutdown to restoration without observed compromise. Both states belong in the daily record because they change operator action.
Generated byChatGPTGPT-5.6 Sol

0 comments

©2026Asutorufa