September 28, 2026
Command View
Verification cutoff
September 28, 2026, 14:34 UTC. Two newly disclosed and exploited Citrix NetScaler flaws dominate the operational picture. A separate Kiteworks precautionary shutdown has ended without a publicly confirmed compromise. ServiceNow AI Platform fixes and GitLab's additional supported backports require targeted supplier review.
Priority posture
- RED: Citrix reports exploitation of two NetScaler remote-code-execution flaws before fixes became available. Exposed, unremediated customer-managed appliances need immediate isolation or tightly controlled access, evidence preservation, compromise assessment, and upgrade.
- AMBER: ServiceNow AI Platform flaws can expose or alter instance data under the stated conditions; no exploitation was reported by the reviewed government advisory.
- WATCH: Kiteworks lifted its precautionary shutdown recommendation September 27. Its public statement still describes a possible threat, not a confirmed intrusion or a disclosed new vulnerability.
- CONTEXT: GitLab's September 23 backports expand the repair options for an earlier exploited file-read flaw; they do not establish a new campaign today.
Today's decisions
- RED — Network and incident-response owners: Inventory all customer-managed NetScaler ADC and Gateway instances, including private application entry points; preserve logs and appliance evidence where feasible; assess compromise and deploy branch-specific fixes. Prioritize internet-reachable devices without overlooking internally reachable ones.
- RED — Identity and recovery owners: For suspicious NetScaler instances, investigate downstream authentication, sessions, secrets and certificates; prepare trusted replacement rather than treating an upgrade as incident closure.
- AMBER — ServiceNow platform owner: Confirm the assigned instance patch or hotfix against ServiceNow's product-specific advisory and review access to sensitive workflows and instance data.
- WATCH — File-transfer and continuity owners: Follow Kiteworks' September 27 restart notice, confirm service recovery and version 9.5.1, and monitor direct customer communications for any revised forensic or patch guidance.
Threat and Resilience Ledger
[RED] — Remote-access and application edge | Global product exposure — Citrix confirms exploitation of two NetScaler zero-days
Citrix's September 27 bulletin confirms exploitation on unmitigated, customer-managed NetScaler ADC and NetScaler Gateway deployments of CVE-2026-88771 and CVE-2026-88772 before fixes were available. The first allows unauthenticated arbitrary commands on affected appliances without an optional feature. The second can cause code execution or denial of service where DTLS is enabled; DTLS is enabled by default on VPN virtual servers. CISA placed both in its Known Exploited Vulnerabilities catalog and described global exploitation; Canada and the UK issued urgent notices. Remote-access, authentication and application-delivery roles make appliance and downstream trust consequential, but these statements do not establish compromise of every exposed device. Capture evidence before disruptive changes where feasible, isolate suspected systems, use Citrix's indicators as an initial screen, and upgrade to the appropriate fixed branch. A negative indicator scan is not proof of safety.
Evidence: vendor-confirmed exploitation and government KEV listings. Attribution: unknown. Confidence: high. Uncertainty: affected victim population, persistence methods and completeness of available indicators. Sources: Citrix — “Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778,” September 27; CISA — “Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway,” September 27; Canadian Centre for Cyber Security — “AL26-024,” September 27; UK NCSC — “Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway,” September 28.
[AMBER] — Enterprise workflow and data control plane | Global product exposure — ServiceNow AI Platform receives multiple security fixes
The Canadian Cyber Centre's September 25 advisory lists affected ServiceNow AI Platform releases, following ServiceNow's September 24 disclosure. The Multi-State Information Sharing and Analysis Center describes five issues: authenticated unauthorized data access (CVE-2026-86857) and, in specified circumstances, unauthenticated data creation or modification (CVE-2026-86858), SQL injection against instance data (CVE-2026-13016), unauthorized data access (CVE-2026-86859) and data extraction with potential privilege escalation (CVE-2026-86860). This is consequential where the platform orchestrates administrative or operational workflows. The reviewed government advisory reports no exploitation in the wild; do not infer a breach. Confirm the precise Australia, Yokohama or Zurich patch or hotfix applicable to the instance with the vendor and review abnormal data access or workflow changes if exposure existed.
Evidence: government and MS-ISAC advisories describing vendor-remediated flaws; no reported exploitation in the reviewed advisory. Attribution: not applicable. Confidence: high for issue descriptions; moderate for deployment-specific exposure without vendor instance confirmation. Uncertainty: exact exposure of individual tenants and whether private incident reports emerge. Sources: Canadian Centre for Cyber Security — “ServiceNow security advisory (AV26-963),” September 25; Center for Internet Security/MS-ISAC — “Multiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized Access,” September 25.
[WATCH] — Secure file exchange and supplier continuity | Global customer operations — Kiteworks ends precautionary shutdown
Kiteworks said September 25 that federal intelligence authorities had provided credible information about a threat actor potentially targeting some Kiteworks systems. The company recommended a temporary nine-hour shutdown for self-managed and hosted customers, expressly said it had no indication of customer or company compromise, and stated that release 9.5.1 addressed all vulnerabilities then known to it. Its subsequently posted September 27 notice lifted the shutdown recommendation for all customers, said hosted systems were operating normally and directed self-hosted Advanced Forms customers to support. The notice establishes a real availability intervention and a changed restart decision, but identifies no CVE, attack path, confirmed exploit or victim. Restore services under the vendor notice and verify transfer queues, integrations and logs; seek customer-specific guidance from Kiteworks if anomalies appear.
Evidence: direct vendor statement and September 27 update. Attribution: unknown; targeting intelligence was not publicly detailed. Confidence: high for the advisory and changed operating posture; low for any inference about a vulnerability or attacker success. Uncertainty: underlying intelligence and whether a later technical or incident notice will alter the assessment. Sources: Kiteworks — “Kiteworks Issues Precautionary Shutdown Advisory for Customers Following Credible Threat Intelligence From Federal Intelligence Authorities,” September 25, notice updated September 27.
[CONTEXT] — Source-control and build trust | Global product exposure — GitLab expands fixes for previously exploited file-read flaw
GitLab updated its September 10 critical-patch notice on September 23 to add 19.0.9 and 18.11.12 as backported fixes for CVE-2026-85706 and CVE-2026-87719 in self-managed Community and Enterprise editions. The former is an earlier KEV-listed, unauthenticated server-file-read issue; its exposure can implicate repository secrets and CI/CD credentials. This is a material repair-path change for administrators who remain on those supported branches, not evidence of fresh exploitation today. Verify the latest supported patch for the installed branch and assess whether sensitive files could have been read before the fix; rotate specific exposed secrets if investigation supports it. GitLab says GitLab.com is patched and GitLab Dedicated customers need no action for the cited patch notice.
Evidence: vendor patch-release update and prior KEV designation. Attribution: unknown. Confidence: high for backport versions; moderate for any particular installation's prior secret exposure. Uncertainty: complete exploitation scope and which files, if any, were obtained from individual instances. Sources: GitLab — “GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8,” September 10, updated September 23; Canadian Centre for Cyber Security — “GitLab security advisory (AV26-917),” updated September 2026.
Defensive Posture Changes
Preserve the edge before rebuilding it
Where NetScaler compromise is plausible, retain appliance and remote syslog data, configuration, support bundles and correlated identity records before patching or rebooting when operationally feasible. Limit exposure during triage. Examine processes, startup scripts, web directories, outbound connections and connected hosts. A clean Citrix indicator scan has limited forensic value; confirmed compromise calls for trusted rebuild or replacement and validation of connected identities and certificates.
Match fixes to configuration and branch
NetScaler CVE-2026-88771 needs no optional feature; disabling DTLS only affects the second flaw's precondition. For 13.1, Citrix warns that upgrading to 13.1-64.23 can cause a reboot cycle if show ns variable returns configured variables; use 13.1-64.24 in that case. Citrix also says CVE-2026-88778 requires enabling Enhanced ISN Generation; the software upgrade alone does not remediate that separate issue.
Validate supplier recovery and workflow integrity
For Kiteworks, reconcile queued transfers and dependent services after restart, especially Advanced Forms if self-hosted. For ServiceNow, establish the actual applied tenant patch with the supplier and check high-value workflow and data changes. For GitLab, treat possible file read as a potential secret-exposure question, not merely a version check.
Regional and Sector Pulse
- North America — RED: CISA and Canada's Cyber Centre independently escalated the Citrix issue. Their notices establish global exploitation and exposure, not a count of North American victims.
- Europe/UK — RED: The UK NCSC urges prompt mitigation and says it is still assessing UK impact. CERT-EU also issued a Citrix advisory; no distinct European victim count is established here.
- Indo-Pacific, including India — RED for affected installations: Singapore's cyber agency published a September 28 Citrix alert. That publication does not establish local compromise or targeting.
- Africa; Middle East; Asia outside the Indo-Pacific grouping; Russia; China; Latin America/Caribbean — WATCH: No separate regional victim pattern was verified for the selected developments. Apply the product-specific posture to local deployments without assigning geography to an unreported campaign.
- Cross-sector operations — WATCH: Kiteworks' precautionary interruption matters to organizations that depend on secure file movement; the vendor says its shutdown advice has ended. Critical-sector service outages or confirmed compromise were not established by the public statement.
Vulnerability and Supplier Watchlist
Citrix NetScaler ADC and NetScaler Gateway
Issue: CVE-2026-88771, unauthenticated command execution; CVE-2026-88772, remote code execution or denial of service when DTLS is enabled.
Affected scope: customer-managed ADC/Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23; ADC FIPS 14.1 before 14.1-73.37 FIPS; ADC FIPS/NDcPP 13.1 before 13.1-37.279. CVE-2026-88771 needs no optional feature; CVE-2026-88772 requires DTLS.
Fixed release: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS or 13.1-37.279 FIPS/NDcPP, respectively, or later in branch. Use 13.1-64.24 if the vendor's configured-variable reboot warning applies.
Severity: Citrix CVSS v4.0 9.5 for each.
Status: RED — Citrix confirms exploitation of both; CISA lists both in KEV.
ServiceNow AI Platform
Issue: CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859 and CVE-2026-86860; unauthorized instance data access or modification under issue-specific conditions.
Affected scope: named Australia, Yokohama and Zurich patch/hotfix levels in the vendor and Canadian advisories; verify the exact assigned tenant release.
Fixed release: vendor-specific Australia, Yokohama or Zurich hotfix/patch; confirm applicability with ServiceNow rather than assuming one universal build.
Severity: consult the vendor record for each CVE; no aggregate score assigned here.
Status: AMBER — control-plane/data consequence; no in-the-wild exploitation reported in the reviewed MS-ISAC advisory.
Kiteworks
Issue: precautionary supplier alert concerning possible targeting; no CVE or new exploit disclosed publicly.
Affected scope: precautionary interruption covered hosted and self-managed Kiteworks systems; self-hosted Advanced Forms customers need vendor support for restart.
Fixed release: no newly identified flaw or fix published by cutoff; Kiteworks identifies 9.5.1 as addressing all vulnerabilities known to it.
Severity: no vulnerability score applicable.
Status: WATCH — shutdown recommendation lifted September 27, with no public indication of compromise.
GitLab CE/EE
Issue: CVE-2026-85706, prior KEV-listed unauthenticated server-file read; September 23 backports also cover CVE-2026-87719.
Affected scope: self-managed affected branches; match inventory to GitLab's release notice.
Fixed release: backports 18.11.12 and 19.0.9; earlier 19.1.8, 19.2.6 and 19.3.2 fixes; use the latest supported patch for the branch.
Severity: GitLab rates CVE-2026-85706 critical; consult its advisory for the score of each distinct flaw.
Status: CONTEXT — new remediation options for an existing exploited issue.
Outlook and Uncertainty
Next 24 hours
Watch Citrix for revised indicators, forensic guidance and version caveats; watch CISA and national CERTs for additional victim or remediation detail. Check for a technical Kiteworks follow-up and any change in ServiceNow exploitation reporting. Validate the GitLab backports in local inventories.
What is not known
Citrix and government alerts do not identify the complete victim set, persistence paths or attribution. Citrix warns that its indicators are incomplete. Kiteworks has not publicly specified the threat information underlying its shutdown decision or disclosed a new defect. The public ServiceNow advisories do not establish individual customer impact.
Trigger for escalation
Any unexpected NetScaler process, modified file, suspicious session or downstream credential use triggers incident response and trusted restoration. Confirmed ServiceNow instance exploitation or unauthorized workflow changes would move that item to RED. A Kiteworks notice identifying actual compromise, a specific exploitable flaw or customer-impact evidence would likewise change its posture.
Sources
Citrix NetScaler
Citrix — “Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778,” September 27, 2026:
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/
Citrix — “Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin,” CTX697096:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
CISA — “Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway,” September 27, 2026 (CISA bulletin delivery page):
https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42cc465
Canadian Centre for Cyber Security — “AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway,” September 27, 2026:
https://www.cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772
UK National Cyber Security Centre — “Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway,” September 28, 2026:
https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
Cyber Security Agency of Singapore — “Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway,” September 28, 2026:
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129/
ServiceNow AI Platform
Canadian Centre for Cyber Security — “ServiceNow security advisory (AV26-963),” September 25, 2026:
https://www.cyber.gc.ca/en/alerts-advisories/servicenow-security-advisory-av26-963
Center for Internet Security/MS-ISAC — “Multiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized Access,” September 25, 2026:
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-servicenows-ai-platform-could-allow-for-unauthorized-access_2026-102
Kiteworks
Kiteworks — “Kiteworks Issues Precautionary Shutdown Advisory for Customers Following Credible Threat Intelligence From Federal Intelligence Authorities,” September 25, 2026, with September 27 update:
https://www.kiteworks.com/company/press-releases/kiteworks-precautionary-shutdown-advisory/
GitLab
GitLab — “GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8,” September 10, 2026, updated September 23:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
Canadian Centre for Cyber Security — “GitLab security advisory (AV26-917),” September 2026:
https://www.cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917
This briefing is intended for defensive awareness and operational decision-making, not as a substitute for incident response, vendor guidance, or legal advice.
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: