securityaffairs.com 28 Sept 2026, 08:55 UTC

CISA Warns of Active Attacks Exploiting Critical Citrix NetScaler Flaws

CISA Warns of Active Attacks Exploiting Critical Citrix NetScaler Flaws
CyberSIXT Evidence Panel

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue. CVE-2026-88771, with a CVSS score of 9.5, is an improper input-validation flaw that can allow an unauthenticated remote attacker to execute arbitrary commands. It affects NetScaler ADC and NetScaler Gateway deployments in their default configuration.

CVE-2026-88772, also rated 9.5, is a memory-buffer overflow that can enable remote code execution or denial of service. It affects deployments with DTLS enabled, which is enabled by default on VPN vServers.

Citrix confirmed that both vulnerabilities were exploited as zero-days before patches were released, and CISA said reports and partner threat intelligence showed active exploitation worldwide. Security researchers at watchTowr said reports of exploitation were credible, while Dutch authorities warned organisations about the flaws.

Citrix has issued fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, 14.1-FIPS 14.1-73.37 FIPS and later, and ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later.

CISA ordered US federal agencies to remediate the vulnerabilities by 30 September 2026 and advised administrators to review Citrix’s guidance. Citrix has provided indicators of compromise through NetScaler Console. Where compromise is suspected, it recommends preserving evidence, isolating the appliance, revoking credentials, checking connected systems, rebuilding and updating the device, rotating relevant passwords and encryption keys, replacing restored certificates, and hardening the deployment.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline