U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
September 28, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-88771 (CVSS score: 9.5) Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 (CVSS score: 9.5) Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote attacker to execute arbitrary commands. The flaw affects all NetScaler ADC and NetScaler Gateway deployments in their default configuration and does not require any additional features to be enabled.

CVE-2026-88772 (CVSS score: 9.5) is a memory buffer overflow vulnerability that could allow remote code execution or cause a denial-of-service condition. The flaw affects NetScaler ADC and NetScaler Gateway deployments with DTLS enabled, which is enabled by default on VPN vServers. The vulnerability is classified as CWE-119.

This week, Citrix confirmed that the two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The first warnings did not come from Citrix. On September 26, administrators said IT providers and security teams were privately advising them to take NetScaler systems offline, sometimes without explaining why.

The two zero-day issues are not related to NetScaler vulnerabilities CVE-2026-19490 and CVE-2026-19489 that were disclosed in August.

The reports show how the attacks were already underway while defenders were still waiting for official details and fixes.

Security researchers at watchTowr then confirmed that the reports were credible. The company said it was investigating reports of multiple unpatched NetScaler remote code execution flaws being exploited in the wild and later said the vulnerabilities had been found during forensic investigations.

“We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible,” watchTowr wrote on X.

The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands. According to a notice seen by BleepingComputer, a European partner CERT had shared information about two critical NetScaler zero-days that could allow remote code execution. One of the flaws could even let an attacker inject shellcode directly into memory.

Both vulnerabilities have been fixed in the following NetScaler releases:

  • Citrix NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
  • Citrix NetScaler ADC and NetScaler Gateway 13.1-64.23 and later
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later

CISA said it has received reports and threat intelligence confirming that attackers are actively exploiting the vulnerabilities worldwide.

“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.” reads the advisory published by CISA. “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories.”

CISA also noted that updating NetScaler appliances can be complex and may require downtime. The alert is intended to help organizations assess their exposure, prioritize mitigation and include the vulnerabilities in their risk management plans.

Citrix has also released generic indicators of compromise (IoCs) through NetScaler Console. These can help customers check whether their systems may have been compromised.

If a compromise is suspected, Citrix recommends taking the following steps:

  • Preserve evidence from the NetScaler ADC VPX instance.
  • Isolate the device.
  • Revoke credentials and access.
  • Check connected servers and systems for signs of further compromise.
  • Rebuild the device and update it to the latest firmware.
  • Rotate local account passwords and Key Encryption Keys (KEK), and replace restored SSL certificates when recovering from a known-good backup.
  • Harden the device according to Citrix security best practices.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by September 30, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.