CISA KEV Alert 27 Sept 2026, 23:02 UTC

CISA Warns NetScaler Flaw Is Being Exploited for Command Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway and is an improper input validation flaw that could allow an unauthenticated attacker to execute arbitrary commands.

The flaw allows specially crafted input to reach command execution functionality without authentication. NVD assigns it a CVSS score of 9.5, rated Critical. The available data does not confirm whether a patch is available.

CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. Ransomware use is unknown. CISA has set 30 September 2026 as the remediation deadline. Citrix customers should also conduct forensic triage and use the provided indicators of compromise to check for exploitation.

CISA requires organisations to apply mitigations in accordance with Citrix’s instructions and BOD 26-04, including its requirements for prioritising security updates and forensic triage. If mitigations are unavailable, organisations should follow the applicable BOD 26-04 guidance for cloud services or discontinue use of the product. Federal Civilian Executive Branch (FCEB) agencies are directly subject to this requirement, but all organisations should review their NetScaler exposure and internet-facing assets.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline