CISA Orders Federal Agencies to Secure Citrix NetScaler Zero-Days Under Active Attack
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to protect their systems against attacks exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances.
Tracked as CVE-2026-88771 and CVE-2026-88772, the flaws are being actively exploited as zero-days. Citrix has released security updates and urged customers to patch affected appliances immediately.
The warning follows days of private alerts from national cybersecurity agencies, IT suppliers, and security teams advising Citrix customers to shut down or secure their NetScaler appliances.
Critical NetScaler flaws allow unauthenticated remote code execution
Both vulnerabilities can allow an unauthenticated attacker to execute remote code on a vulnerable NetScaler appliance.
- CVE-2026-88771: Affects all NetScaler ADC and NetScaler Gateway deployments with default configurations.
- CVE-2026-88772: Requires DTLS to be enabled. Citrix notes that DTLS is enabled by default for VPN virtual servers.
The Netherlands National Cyber Security Center (NCSC-NL) reportedly alerted organizations in the Netherlands about two critical NetScaler zero-days that allowed threat actors to place shellcode directly into memory without a CVE identifier.
Citrix confirmed on Sunday that both vulnerabilities were being exploited in zero-day attacks.
“We have observed exploitation of CVE-2026-88771 and CVE-2026-88772 in unmitigated NetScaler deployments. Citrix strongly recommends affected customers install the relevant updated versions as soon as possible,” the company said.
Citrix’s security bulletin covers vulnerabilities that vary by deployment configuration and enabled functionality. The issues include potential remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under certain conditions.
Citrix warns that indicators of compromise have limited forensic value
Citrix has shared what it calls “common indicators of compromise” through the NetScaler Console to help security teams identify potentially compromised deployments.
However, the company warned that these indicators of compromise have “limited forensic value and may not identify the actual breach.” Citrix advised customers to retain the services of an experienced forensic investigator if they suspect an intrusion.
Security teams should also consider preserving forensic evidence before applying updates, as patching can result in a loss of forensic visibility.
More than 23,000 NetScaler instances exposed online
Threat monitoring organization Shadowserver currently tracks more than 23,000 internet-exposed IP addresses using NetScaler fingerprints. The figure includes approximately 22,000 NetScaler ADC appliances and just over 1,500 NetScaler Gateway instances.
Shadowserver’s data does not show how many of the systems are honeypots, whether they have already been patched, or whether they use vulnerable configurations.

CISA adds CVE-2026-88771 and CVE-2026-88772 to its KEV catalog
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog.
Under Binding Operational Directive 26-04, CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable Citrix appliances by September 30.
“Given the potential impact if successful exploitation and the fact that malicious attackers are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s recommendations,” the agency warned.
CISA also recommends checking for indicators of compromise before applying a patch when possible. Organizations that suspect a compromise should preserve forensic evidence before updating their appliances.
Citrix NetScaler vulnerabilities repeatedly exploited in 2026
The two zero-days are the latest in a series of Citrix NetScaler vulnerabilities exploited in the wild since the beginning of the year.
In March, Citrix urged administrators to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, days before attackers began exploiting them.
More recently, attackers began exploiting the NetScaler authentication bypass vulnerability CVE-2026-19490 in early September. Citrix patched the vulnerability in mid-August.
Since November 2021, CISA has reported 26 actively exploited Citrix vulnerabilities. Six of those vulnerabilities were exploited by ransomware gangs.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



