INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability

| 2026-10-09 08:11 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 9, 2026, a critical vulnerability (CVE-2026-107406) was discovered in Citrix NetScaler ADC and Gateway software versions prior to 14.1-73.46 and 13.1-64.29, allowing remote code execution or denial-of-service attacks under specific configuration conditions. The identified entity behind the vulnerability is JPMorgan Chase XOR Team, consisting of Michael Tucker, Chew Keong Tan, and Alex Bernier. This vulnerability affects approximately 100,000 customers worldwide who have NetScaler ADC and Gateway software installed in customer-managed deployments running vulnerable versions. The attack works by exploiting a memory overflow vulnerability that can cause denial-of-service under specific conditions. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits or attacks in the wild exploiting this vulnerability; however, customers are urged to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-19490, CVE-2026-88775 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

cl•••••.random
wa•••••.py
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-19490CVE-2026-19490 CVE-2026-88775CVE-2026-88775 CVE-2026-88774CVE-2026-88774 CVE-2026-107406CVE-2026-107406 CVE-2026-19489CVE-2026-19489 CVE-2026-88773CVE-2026-88773 CVE-2026-88777CVE-2026-88777 CVE-2026-88778CVE-2026-88778 CVE-2026-88776CVE-2026-88776 CVE-2026-88771CVE-2026-88771 CVE-2026-88772CVE-2026-88772 CVE-2026-88779CVE-2026-88779 CVE-2026-8452CVE-2026-8452
Target & Sectors
NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX governmentgovernment
Incident Timeline
‎September 2025
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, starting in September 2025.
‎August 19
Threat actors used the unpatched Citrix NetScaler vulnerabilities, including CVE-2026-19490, to target state hackers for weeks.
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-19490
attribution Known Exploited
‎2026/08/28
State hackers had exploited a Citrix NetScaler vulnerability that was exposed for weeks after organizations patched the software last month.
‎September 9
Threat actors exploited a previously unpatched Citrix NetScaler vulnerability, CVE-2026-19490, added to the CISA Known Exploited Vulnerabilities catalog on September 9.
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-19490
attribution Known Exploited
‎September 15
Threat actors exploited the unpatched Citrix NetScaler 13.1 ADC vulnerability for weeks prior to its End of Maintenance on September 15.
infrastructure 13.1
general_metric 13.1 NetScaler ADC
‎September 26
Threat actors are actively exploiting two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances for remote code execution.
tactic Remote Code Execution
organisation NetScaler Gateway
organisation Citrix NetScaler ADC
organisation Vulnerability / Network Security
general_metric 27 Sep
organisation NetScaler RCE
‎September 27, 2026
Threat actors exploited two newly discovered Citrix NetScaler zero-day vulnerabilities before patches were made available, allowing them to remotely execute code.
organisation NetScaler
‎Sep 27, 2026
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, allowing state hackers to access the system.
‎September 27
Citrix published fixes for the two exploited vulnerabilities on September 27.
‎2026/09/28
Threat actors used the improperly validated input in NetScaler 14.1 build 73.30 to run arbitrary commands, exploiting CVE-2026-88771, and then later updated to use the same vulnerability in build 73.37, also known as CVE-2026-88772.
vulnerability CVE-2026-88771
vulnerability CVSS 4.0
organisation Improper
general_metric 4.0 CVSS
general_metric 14.1 NetScaler
vulnerability CVE-2026-88772
infrastructure 14.1
infrastructure 73.30
infrastructure 73.37
organisation Patch Diffing Contrary
general_metric 73.30 Different
general_metric 73.37 Diffing Contrary
‎early in the week of September 28
Threat actors exploited two unpatched remote code execution vulnerabilities in Citrix NetScaler for weeks before patches were expected to be released early in the week of September 28.
tactic Remote Code Execution
organisation UTC
‎2026/09/29
Threat actors exploited CVE-2026-88772 in Citrix NetScaler for weeks, starting from September 29, 2026.
vulnerability CVE-2026-88772
organisation Citrix NetScaler
‎Sep 30, 2026
Threat actors exploited a Citrix NetScaler vulnerability that had been exposed to state hackers for weeks, allowing them unauthorized access.
‎September 30, 2026
State hackers were exposed to a Citrix NetScaler vulnerability for approximately 8 weeks prior to the incident being reported on September 30, 2026.
‎2026/09/30
Federal civilian agencies failed to remediate and perform forensic triage of the exposed Citrix NetScaler vulnerability, which was publicly disclosed for weeks prior.
‎2026/10/01
CISA has set a deadline for federal civilian agencies to remediate and perform forensic triage by September 30, 2026.
attribution CISA
‎October 5, 2026
Threat actors successfully exploited a Citrix NetScaler vulnerability that exposed the ADC or Gateway to be configured as an IdP for weeks prior to October 5, 2026.
organisation NetScaler ADC
organisation IdP
‎October 7, 2026
The US government's Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to address a Citrix NetScaler vulnerability that was potentially exposed to state hackers for weeks prior to the October 7, 2026 deadline.
‎Oct 09, 2026
Threat actors exploited a Citrix NetScaler vulnerability that remained unpatched for weeks, allowing state hackers to access the system.
‎2026-88779
State hackers have been actively exploiting three different Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) for weeks.
‎2026-88771
Threat actors used the Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) to target state hackers for weeks.
‎2026-88772
State hackers have been actively exploiting three different Citrix NetScaler vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) for weeks.
‎2026/10/09
Threat actors used a memory overflow vulnerability in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88779, to cause denial-of-service under specific deployment conditions.
organisation Vulnerability / Network Security Citrix
organisation NetScaler ADC
organisation NetScaler Gateway
organisation DoS
organisation CVE-2026-107406
infrastructure 9.5
organisation TCP
organisation DTLS
organisation NetScaler
organisation CVE-2026
organisation Citrix NetScaler ADC
organisation CVSS
infrastructure 14.1-73
infrastructure 14.1-FIPS
infrastructure 13.1-64
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
infrastructure 13.1-37
infrastructure 13.1
infrastructure 37.282
infrastructure 14.1 FIPS
infrastructure 73.37 FIPS
financial 73.37 NetScaler
infrastructure 13.1.37
infrastructure 13.1 FIPS
organisation SAML Identity Provider (IdP
infrastructure 14.1
organisation NetScaler Gateway 14.1
organisation NetScaler ADC FIPS
financial 14.1 NetScaler ADC
infrastructure 73.41 NetScaler ADC FIPS
organisation FCEB
infrastructure Cursor
organisation @@ copy_saved_header(scratch
organisation scratch + saved_header_length
infrastructure 13.1-63
organisation CVE-2026-88779
organisation Chase XOR Team
organisation IdP
organisation KeV
data_breach 1 byte
data_breach 120 bytes
organisation PoC
organisation NetScaler CVE-2026-88772
organisation the Datagram Transport Layer Security
organisation the NetScaler Packet Processing Engine
organisation NSPPE
organisation PreAuth
data_breach 7 bytes
organisation Citrix NetScaler Gateway
organisation Identity Provider (IdP
organisation SecurityAffairs
organisation Known Exploited
organisation Denial of Service
organisation AAA
organisation Citrix NetScaler
organisation MDR
organisation the Dutch National Cyber Security Centre
organisation NCSC-NL
organisation TLP
organisation NetScalers
data_breach 1,459 bytes
data_breach 13 byte
data_breach 12 byte
data_breach 2 record
infrastructure 50,000 Devices
organisation Content Type
organisation Kheirkhah
infrastructure 3 server
organisation NetScaler Buffers
data_breach 35,840 bytes
organisation NSB
organisation NULL
infrastructure 8.8
organisation Preemptive Exposure Management
organisation The Hacker News
organisation SSL
organisation TLS
organisation UDP
data_breach 137,825 bytes
data_breach 1,447 bytes
organisation @@
organisation mov r15d
organisation IP
organisation ClientHello
organisation RCX
organisation gdb
financial $1 $ rcx
organisation PIE
organisation MB
data_breach 41 MB binary
organisation ROP
organisation RDX -> 0x7
organisation |_\
organisation External Attack Surface Management
data_breach 1,315 remaining bytes
organisation National Cyber Security Center
organisation WatchTowr
organisation Citrix Bleed
organisation Two New NetScaler Flaws Exploited
organisation NetScaler RCE
organisation NetScaler Console
organisation VPX
organisation Keep
organisation The NetScaler Management Services
Tactical Metrics
Metrics
infrastructure
‎14.1-73
Software Version
Metrics
infrastructure
‎14.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-64
Software Version
Metrics
infrastructure
‎13.1-FIPS
Software Version
Metrics
infrastructure
‎13.1-NDcPP
Software Version
Metrics
infrastructure
‎13.1-37
Software Version
Metrics
infrastructure
‎13.1
Software Version
Metrics
infrastructure
‎37.282
Software Version
Metrics
infrastructure
14
Fips
Metrics
infrastructure
73
Fips
Metrics
financial
73
Netscaler
Metrics
infrastructure
‎13.1.37
Software Version
Metrics
infrastructure
13
Fips
Metrics
infrastructure
‎9.5
Software Version
Metrics
infrastructure
‎14.1
Software Version
Metrics
financial
14
Netscaler Adc
Metrics
infrastructure
73
Netscaler Adc Fips
Metrics
infrastructure
50,000
Devices
Metrics
data_breach
1
Byte
Metrics
data_breach
120
Bytes
Metrics
data_breach
1,459
Bytes
Metrics
data_breach
35,840
Bytes
Metrics
infrastructure
‎8.8
Software Version
Metrics
infrastructure
‎73.30
Software Version
Metrics
infrastructure
‎73.37
Software Version
Metrics
infrastructure
‎Cursor
Affected Product
Metrics
data_breach
7
Bytes
Metrics
data_breach
13
Byte
Metrics
data_breach
12
Byte
Metrics
data_breach
1,447
Bytes
Metrics
data_breach
137,825
Bytes
Metrics
financial
1
$ Rcx
Metrics
data_breach
41
Mb Binary
Metrics
data_breach
1,315
Remaining Bytes
Metrics
data_breach
2
Record
Metrics
infrastructure
3
Server
Metrics
infrastructure
‎13.1-63
Software Version