Sep 28 / Latest News

CISA Adds Two Actively Exploited Citrix NetScaler Vulnerabilities to KEV Catalog Amid Global Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical Citrix NetScaler ADC and Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation across global environments.

Both flaws carry CVSS scores of 9.5 and enable unauthenticated command execution, remote code execution, or denial‑of‑service depending on configuration. CVE‑2026‑88771 affects all NetScaler ADC and Gateway deployments, while CVE‑2026‑88772 requires DTLS to be enabled — a default setting on VPN virtual servers.

The DTLS‑dependent configuration is commonly present in environments using: add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE Citrix has released patches across supported branches, including NetScaler ADC and Gateway 14.1‑73.37 and later, 13.1‑64.23 and later, 14.1‑FIPS 14.1‑73.37 and later, and 13.1‑FIPS/13.1‑NdC PP 13.1.37.279 and later. CISA noted that updating NetScaler appliances can be complex and may require downtime, urging organizations to prioritize mitigation and incorporate the vulnerabilities into risk‑management activities.

Citrix also published generic indicators of compromise (IoCs) through the NetScaler Console to help customers determine whether their appliances have been impacted. If compromise is suspected, recommended actions include preserving evidence, isolating the device, revoking credentials, investigating connected systems for lateral movement, rebuilding and updating firmware, rotating passwords and keys, replacing restored SSL certificates, and hardening the device according to best practices. Due to active exploitation, Federal Civilian Executive Branch agencies must apply the fixes by September 30, 2026.