Sep 28
/
Latest News
CISA Adds Two Actively Exploited Citrix NetScaler Vulnerabilities to KEV Catalog Amid Global Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical Citrix NetScaler ADC and Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation across global environments.
Both flaws carry CVSS scores of 9.5 and enable unauthenticated command execution, remote code execution, or denial‑of‑service depending on configuration. CVE‑2026‑88771 affects all NetScaler ADC and Gateway deployments, while CVE‑2026‑88772 requires DTLS to be enabled — a default setting on VPN virtual servers.
The DTLS‑dependent configuration is commonly present in environments using: add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE Citrix has released patches across supported branches, including NetScaler ADC and Gateway 14.1‑73.37 and later, 13.1‑64.23 and later, 14.1‑FIPS 14.1‑73.37 and later, and 13.1‑FIPS/13.1‑NdC PP 13.1.37.279 and later. CISA noted that updating NetScaler appliances can be complex and may require downtime, urging organizations to prioritize mitigation and incorporate the vulnerabilities into risk‑management activities.
Citrix also published generic indicators of compromise (IoCs) through the NetScaler Console to help customers determine whether their appliances have been impacted. If compromise is suspected, recommended actions include preserving evidence, isolating the device, revoking credentials, investigating connected systems for lateral movement, rebuilding and updating firmware, rotating passwords and keys, replacing restored SSL certificates, and hardening the device according to best practices. Due to active exploitation, Federal Civilian Executive Branch agencies must apply the fixes by September 30, 2026.
Both flaws carry CVSS scores of 9.5 and enable unauthenticated command execution, remote code execution, or denial‑of‑service depending on configuration. CVE‑2026‑88771 affects all NetScaler ADC and Gateway deployments, while CVE‑2026‑88772 requires DTLS to be enabled — a default setting on VPN virtual servers.
The DTLS‑dependent configuration is commonly present in environments using: add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE Citrix has released patches across supported branches, including NetScaler ADC and Gateway 14.1‑73.37 and later, 13.1‑64.23 and later, 14.1‑FIPS 14.1‑73.37 and later, and 13.1‑FIPS/13.1‑NdC PP 13.1.37.279 and later. CISA noted that updating NetScaler appliances can be complex and may require downtime, urging organizations to prioritize mitigation and incorporate the vulnerabilities into risk‑management activities.
Citrix also published generic indicators of compromise (IoCs) through the NetScaler Console to help customers determine whether their appliances have been impacted. If compromise is suspected, recommended actions include preserving evidence, isolating the device, revoking credentials, investigating connected systems for lateral movement, rebuilding and updating firmware, rotating passwords and keys, replacing restored SSL certificates, and hardening the device according to best practices. Due to active exploitation, Federal Civilian Executive Branch agencies must apply the fixes by September 30, 2026.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.