Cybersecurity Radar — 2026-09-28
The dominant story this cycle is Citrix's confirmation that two critical NetScaler ADC/Gateway remote code execution zero-days (CVE-2026-88771 and CVE-2026-88772) are being actively exploited in the wild, with emergency patches now released. CISA has added the flaws to its Known Exploited Vulnerabilities catalog. Separately, Kiteworks has urged customers to execute a precautionary nine-hour system shutdown following federal warnings that a threat actor may target some of its deployments.
Cybersecurity Radar — 2026-09-28
🔴 Critical Alerts
Citrix NetScaler RCE zero-days actively exploited — Citrix confirmed two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are under active attack and has released emergency security updates. Both flaws affect NetScaler ADC and Gateway appliances and carry a CVSS v4 score of 9.5. CVE-2026-88772 is a memory overflow in the DTLS implementation, which is enabled by default on NetScaler Gateway VPN virtual servers — meaning the exploitation precondition is met in most production deployments without any configuration change. Then-unpatched versions were publicly disclosed by watchTowr on September 26, before fixes were available. Administrators should apply the fixed builds immediately.
CISA adds NetScaler flaws to KEV catalog — CISA on Sunday added the two Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. CVE-2026-88771 is an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Federal agencies are required to patch under Binding Operational Directive timelines.
Kiteworks urges 9-hour precautionary shutdown — Kiteworks is asking customers to shut down systems for nine hours after federal intelligence warned that a threat actor may target some of its deployments. This emergency advisory is part of this week's notable incident coverage.
Threat Landscape
Ransomware and identity-focused intrusion chains dominate — Threat research this week highlights frequent ransomware and identity-focused intrusion chains, including the "PAYLOAD" actor's abuse of Active Directory GPO/SYSVOL, Qilin's continued cross-sector activity in the ANZ region, and multiple OAuth/session and phishing techniques.

ENISA Threat Landscape 2026: intrusions, suppliers, vulnerabilities — ENISA's Threat Landscape 2026 counts 8,257 incidents, half of them DDoS, with notable findings on intrusions, vulnerability exploitation, ransomware and supplier-related threats.

Bitget breach among weekly incident highlights — This week's intelligence briefing flags the Bitget breach (reported via BleepingComputer, CoinDesk, The Hacker News), August 2026 ransomware statistics from NCC Group, and the Kiteworks emergency advisory.
Vulnerabilities & Patches
- CVE-2026-88771 (CVSS 9.5) — improper input validation in Citrix NetScaler ADC/Gateway allowing unauthenticated arbitrary command execution; exploited in the wild; patch to fixed builds now.
- CVE-2026-88772 (CVSS 9.5) — memory overflow in the DTLS implementation, enabled by default on NetScaler Gateway VPN virtual servers; exploited in the wild.
- CVE-2026-88775 (CVSS v4: 8.8) — a NetScaler memory overflow that can cause unpredictable behavior or denial of service on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Breaches & Incidents
- Bitget cryptocurrency exchange breach — flagged in this week's consolidated intelligence reporting; details remain limited in available sources.
- Kiteworks precautionary shutdown — the secure file-transfer vendor's nine-hour system shutdown directive constitutes an active incident-response posture following federal threat warnings.
Industry & Policy
Ransomware record context persists — NCC Group data shows 1,073 firms fell victim to ransomware globally in August, the highest for 2026, with the industrial sector most affected — a backdrop cited in this week's briefings as agencies and researchers assess monthly trends.

What to Watch
- Additional NetScaler-related advisories: watchTowr has published IOCs and rapid-reaction guidance, and more confirmed exploitation details may emerge as organizations audit their appliances.
- Kiteworks: monitor for follow-up advisories confirming whether the threatened targeting materialized or evolved.
- Qilin's cross-sector ANZ campaign and GPO/SYSVOL-abusing ransomware chains look likely to expand given this week's recurrence patterns.
Reader Action Items
- Audit all Citrix NetScaler ADC and Gateway appliances immediately and upgrade to the fixed builds for CVE-2026-88771 and CVE-2026-88772 — assume exposure, since DTLS is enabled by default on most Gateway deployments.
- Check appliances against watchTowr's published IOCs and review NetScaler logs for signs of prior exploitation.
- If your organization uses Kiteworks, review the vendor's shutdown directive and any coordination guidance before the next business cycle.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.