Summary
CISA has set a specific federal remediation deadline of Wednesday, October 1, 2026 for the two Citrix NetScaler zero-day vulnerabilities documented in TTO-2026-0927-173. Federal agencies must patch CVE-2026-62106 (CVSS 9.8, unauthenticated RCE) and CVE-2026-62107 (CVSS 9.4, authenticated root escalation) or disconnect affected NetScaler ADC and Gateway appliances by that date. TTO-2026-0927-173 reported the CISA KEV addition without a specific deadline; this bulletin records the October 1 mandate.
Timeline
| Date | Event |
|---|---|
| Sep 26-27, 2026 | Citrix releases emergency patches; CISA adds both CVEs to KEV; TTO-2026-0927-173 published without specific federal deadline |
| Sep 27-28, 2026 | CISA issues federal mandate: patch or disconnect by Wednesday October 1, 2026; BleepingComputer reports deadline |
What Changed
TTO-2026-0927-173 noted that CISA had added CVE-2026-62106 and CVE-2026-62107 to its Known Exploited Vulnerabilities catalog but that no specific deadline had been published at time of writing. CISA has now issued that deadline: federal agencies have until Wednesday, October 1, 2026 to apply Citrix’s emergency patches or take affected NetScaler appliances offline. Organizations outside the federal government should treat October 1 as an appropriate urgency benchmark given that CISA sets these deadlines based on its assessment of active targeting of critical infrastructure. Administrators who have not yet applied the emergency patch should do so immediately.
Domain Intelligence
citrix.com — 87.0
Score unchanged from TTO-2026-0927-173. citrix.com scores at 87.0 in the high-trust range.
The Trust Observatory · thetrustobservatory.com · September 28, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026