www.cisa.gov 27 Sept 2026, 12:00 UTC

CISA Flags Actively Exploited Citrix NetScaler Flaws for Patching

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ON 27 September 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The entries are CVE-2026-88771, an improper input validation vulnerability, and CVE-2026-88772, an improper restriction of operations within the bounds of a memory buffer vulnerability. CISA said vulnerabilities of these types are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

CISA’s Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of high-risk KEV vulnerabilities affecting publicly exposed assets that could give an attacker total control after exploitation. It also sets basic expectations for checking whether threat actors compromised systems before patches were applied.

Although the directive applies only to those agencies, CISA encouraged all organisations to use risk-based vulnerability management and prioritise the two newly listed vulnerabilities. The notice did not provide affected NetScaler versions, technical exploitation details or specific patch information.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline