Treasury
3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp 3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp 3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp 3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp 3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp 3-MO 4.24% unch 6-MO 4.33% -1bp 1-YR 4.50% -1bp 2-YR 4.81% -6bp 3-YR 4.94% -5bp 5-YR 4.98% -5bp 7-YR 5.06% -4bp 10-YR 5.17% -1bp 20-YR 5.54% +1bp 30-YR 5.49% +2bp
US Treasury par yield curve · Sep 25 · Source: U.S. Treasury
Monday, September 28, 2026
U.S. Edition
Known exploited flaws

CISA gives agencies three days to patch two exploited Citrix NetScaler flaws

Citrix logo signs in front of a blue-glass office building.
Photo: Alexey Komarov / Wikimedia Commons (CC BY 3.0)

CISA added two Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Sunday after Citrix reported observed attacks on unmitigated systems.

CVE-2026-88771 allows unauthenticated arbitrary commands across default customer-managed ADC and Gateway deployments. CVE-2026-88772 can cause remote code execution or denial of service when DTLS is enabled, which Citrix says is the default on VPN virtual servers.

The clock is short.

CISA set September 30 as the federal due date and requires forensic triage. Citrix says customers should move immediately to the fixed builds: 14.1-73.37 or later, 13.1-64.23 or later, or the listed FIPS and NDcPP versions.

Citrix-managed cloud services are being upgraded by the company.