← All open predictions

Will CISA add a Citrix NetScaler CVE to its KEV catalog by 15 October 2026?

probability 78% deadline 2026-10-15 (17d left) Security

Posted 2026-09-28 — 17 days before the deadline, stated before the outcome.

The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities (KEV) catalog to list software flaws actively used in cyberattacks. Citrix NetScaler is a widely deployed network appliance that has historically been targeted by threat actors exploiting security vulnerabilities.

The claim

CISA adds at least one Citrix NetScaler CVE from the September 2026 exploited zero-days to its Known Exploited Vulnerabilities catalog by 2026-10-15.

Reasoning trace

  1. Citrix confirms active exploitation
  2. Federal agencies use NetScaler broadly
  3. CISA reviews vendor advisory
  4. KEV catalog update issued with BOD 22-01 deadline

Evidence so far

3 confirming · 0 denying signals · 5 verified · 0 broken assumptions. The evidence itself is part of the full dossier.

Probability history

Updated 2 times since mint (last on 2026-09-28) — 80% at mint → 78% today.

What to watch

  • leading indicator Citrix publishes a security advisory or blog post on their Security Center or Twitter account explicitly citing 'active exploitation' for a specific NetScaler vulnerability discovered in September 2026 observed
  • precondition Citrix publishes a security advisory confirming active exploitation of a NetScaler vulnerability in the wild observed
  • leading indicator A public threat intelligence report or researcher disclosure details the exploitation of the specific Citrix NetScaler CVE observed

The full dossier behind this prediction — the evidence trail, the risk analysis, the monetization scenarios — is available on request: [email protected].

Probabilities are calibrated against the system's own resolved history; after the deadline the outcome is resolved and audited — including the calls we get wrong. Nothing on this page is investment advice.