ON 27 September 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The entries are CVE-2026-88771, an improper input validation vulnerability, and CVE-2026-88772, an improper restriction of operations within the bounds of a memory buffer vulnerability. CISA said vulnerabilities of these types are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
CISA’s Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of high-risk KEV vulnerabilities affecting publicly exposed assets that could give an attacker total control after exploitation. It also sets basic expectations for checking whether threat actors compromised systems before patches were applied.
Although the directive applies only to those agencies, CISA encouraged all organisations to use risk-based vulnerability management and prioritise the two newly listed vulnerabilities. The notice did not provide affected NetScaler versions, technical exploitation details or specific patch information.