{"schema":"sb.node.v1","id":"sb:e/e29d1d7fb5415b3e4c2ddd33","kind":"entity","label":{"text":"netscaler gateway","locale":"en"},"identity":{"anchor":"label:en:netscaler gateway","strength":"label"},"asOf":{"knowledgeCutoff":"2026-10-10T20:32:23.797512+00:00","snapshot":"deploy 94d756dba089d5d97cb600fc40d865eb0babacbb"},"lens":{"kind":"public"},"build":{"plane":"projected","builtFrom":["entity_graph.slim.json","entity_receipts (deploy asset)","event_graph.json","truth_records (deploy asset)","corroborated_record.json"],"rule":"node-projection.entity@v1"},"standing":{"evidence":{"supporting":23,"separatePublishers":6,"basis":"documents that mention the subject and the outlets that carried them; a mention is evidence the referent is in use, not evidence about any claim","receiptsOnTopic":{"state":"partial","share":0.348,"named":8,"of":23,"basis":"documents whose own title or summary lead names the subject, over every counted document that mentions it anywhere (the entity graph's measurement); receipts are drawn from the former only","blind":["only 35% of the 23 documents measured name the subject in their own text; the rest mention it in passing, so standing.evidence.supporting overstates coverage about it"]}},"admission":{"state":"provisional","reason":"entity graph provenance 'observed'; the node carries no promotion receipt in v1","policy":"EQ-PROMOTION (receipt not carried)"},"disposition":{"state":"served","reason":"public record"},"validity":{"from":"2026-09-05","to":"2026-10-09","basis":"first and last day we saw it mentioned; not the subject's own lifetime"},"measurement":{"state":"partial","blind":["assertion coverage 0.348: about 65% of mentions carry no typed assertion"]}},"dimensions":{"domains":["cybersecurity","banking_fintech","cloud_computing"],"activeDays":11,"assertions":{"military-action":7,"utterance":1}},"up":[],"upNote":"An entity is a root: it is contained by nothing. Pan out by following R.","children":{"count":8,"byKind":{"observation":8},"items":[{"id":"sb:o/0830d8d1c10549b51520ce5e","kind":"observation","label":"Network World · 2026-10-09 · Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway","url":"https://www.networkworld.com/article/4233186/citrix-issues-its-weekly-critical-security-patch-for-netscaler-adc-and-netscaler-gateway.html"},{"id":"sb:o/d813e57f50f54aec4e430621","kind":"observation","label":"BleepingComputer · 2026-10-09 · Citrix warns admins to patch new NetScaler RCE flaw immediately","url":"https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/"},{"id":"sb:o/dab7302c0a744c32312b5a69","kind":"observation","label":"The Hacker News · 2026-10-09 · Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments","url":"https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html"},{"id":"sb:o/133623f87a28cd4d3bcc4d22","kind":"observation","label":"The Hacker News · 2026-10-01 · Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs","url":"https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html"},{"id":"sb:o/117d02ae9d003c967d47b4e2","kind":"observation","label":"The Hacker News · 2026-09-30 · Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT","url":"https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html"},{"id":"sb:o/a8687f3243f1c428e2f9de3d","kind":"observation","label":"Help Net Security · 2026-09-28 · Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)","url":"https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/"},{"id":"sb:o/9aed41e927858c4ccdc8ddfc","kind":"observation","label":"ABA Banking Journal · 2026-09-28 · CISA issues urgent alert about vulnerabilities in remote access technology used by businesses","url":"https://bankingjournal.aba.com/2026/09/cisa-issues-urgent-alert-about-vulnerabilities-in-remote-access-technology-used-by-banks/"},{"id":"sb:o/aa6f923fe15cf42168438595","kind":"observation","label":"The Hacker News · 2026-09-27 · Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation","url":"https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html"}],"cursor":null,"order":"newest first; we keep the 8 newest receipts for this entity whose own title or summary lead (the entity graph's test) names it. Its other observations are counted in standing.evidence.supporting but are not addressable in v1"},"relations":{"count":10,"byKind":{"co-mentioned":10},"items":[{"kind":"relation","label":"co-mentioned with citrix (23 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/fb6a89e02df6b60bae3b12ac"},{"kind":"relation","label":"co-mentioned with netscaler (23 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/7626b031e0e62518458580d4"},{"kind":"relation","label":"co-mentioned with netscaler adc (18 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/b86771d6149601cc70bb3005"},{"kind":"relation","label":"co-mentioned with cve-2026-88771 (16 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/f09fce2b8759aa9f08dc6ca1"},{"kind":"relation","label":"co-mentioned with cve-2026-88772 (16 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/a0c1ecb590f511718d60f637"},{"kind":"relation","label":"co-mentioned with cisa (15 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/4d80876fbd3fda9cb035b6c1"},{"kind":"relation","label":"co-mentioned with citrix netscaler (15 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/77dab91333107d34fa7e99a7"},{"kind":"relation","label":"co-mentioned with citrix netscaler adc (13 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/bd33ee16886c7697cfa1d1b6"},{"kind":"relation","label":"co-mentioned with cvss (13 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/e4e5d3cde2cb6cba0cfc2e69"},{"kind":"relation","label":"co-mentioned with infrastructure security agency (10 documents)","role":"co-mentioned","relationKind":"co-mentioned","members":2,"id":"sb:r/ba6463661e8b66e37cbf9ca3"}],"cursor":null,"order":"situations first, then claims (the subject's own maintained record, then site-wide corroborated clusters; each label ends with its standing), then co-mentions by shared documents, descending. Co-mentions are the ten strongest the entity graph keeps per entity"},"edge":{"state":"continues"},"links":{"rest":"/api/v1/node/e/e29d1d7fb5415b3e4c2ddd33","mcp":"traverse {\"id\":\"sb:e/e29d1d7fb5415b3e4c2ddd33\"}","page":"/entity/netscaler-gateway/"},"limits":{"levelsPerCall":1,"pageSize":10,"maxPageSize":50,"membersMax":50,"statement":"One level per call: depth is 1 and only 1, and there is no whole-graph dump. pageSize 1-50 (default 10); a page limit is a cursor, never an edge. Members are listed up to 50. At most 60 traverse calls a minute per caller (runaway-loop protection, not a meter). One knowledge cutoff is served: the deploy's."},"actions":[{"verb":"unfold","lit":true,"effect":"read","layer":"cantina","call":"traverse {\"id\":\"sb:e/e29d1d7fb5415b3e4c2ddd33\",\"level\":\"children\"}"},{"verb":"fold","lit":true,"effect":"read","layer":"cantina","call":"traverse {\"id\":\"sb:e/e29d1d7fb5415b3e4c2ddd33\"}"},{"verb":"panOut","lit":false,"effect":"read","layer":"cantina","reason":"An entity is a root: it is contained by nothing. Pan out by following R."},{"verb":"follow","lit":true,"effect":"read","layer":"cantina","call":"traverse {\"id\":\"sb:e/e29d1d7fb5415b3e4c2ddd33\",\"level\":\"relations\"}"},{"verb":"receipts","lit":false,"effect":"read","layer":"cantina","reason":"receipts are the observations below this node; unfold to reach them"},{"verb":"edge","lit":true,"effect":"read","layer":"cantina","call":"traverse {\"id\":\"sb:e/e29d1d7fb5415b3e4c2ddd33\"}"},{"verb":"asOf","lit":false,"effect":"read","layer":"cantina","reason":"v1 serves one knowledge cutoff, this deploy's; walking an earlier cutoff needs retained history (EQ-REPLAY), which v1 does not keep"},{"verb":"switchObserver","lit":false,"effect":"read","layer":"cantina","reason":"the public record is the same for every observer; traversal through a Watch's lens is not served in v1"},{"verb":"readOriginal","lit":false,"effect":"read","layer":"cantina","reason":"no translation is applied on this node; every label is the source's own text"},{"verb":"save","lit":false,"effect":"watch-declaration","layer":"workshop","reason":"saving applies to a configured Watch; configure one around this node first (free), then save it"},{"verb":"deliver","lit":false,"effect":"watch-declaration","layer":"workshop","reason":"delivery applies to a saved Watch"},{"verb":"format","lit":false,"effect":"watch-declaration","layer":"workshop","reason":"output format applies to a saved Watch"},{"verb":"deltaR","lit":false,"effect":"read","layer":"workshop","reason":"Delta R needs a saved Watch with a previous reading"},{"verb":"read","lit":false,"effect":"read","layer":"docking-bay","reason":"one-time Reads are parked until the Commander decides their shape (#938)"}]}