www.cisa.gov 27 Sept 2026, 12:00 UTC

CISA Warns Citrix NetScaler Zero Days Enable Active RCE Attacks

CyberSIXT Evidence Panel

CISA is warning that eight newly disclosed vulnerabilities affect Citrix NetScaler ADC and Citrix NetScaler Gateway: CVE-2026-88771 through CVE-2026-88778. It has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalogue, describing both as critical zero-day flaws that can independently allow remote code execution. CISA says it has received reports and partner threat intelligence confirming that threat actors are actively exploiting the two vulnerabilities globally.

The agency says updating NetScaler appliances can be complex and may require downtime. It is urging organisations to review Citrix’s security advisories, assess their exposure and prioritise mitigation. Where possible, administrators should check for signs of compromise before installing updates. Citrix has made indicators of compromise available through NetScaler Console and published further guidance covering all eight vulnerabilities. Organisations that suspect an intrusion should preserve forensic evidence before patching, because applying updates may reduce forensic visibility.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline