CISA Warns of Active Exploitation of Critical Citrix NetScaler Zero-Days, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning regarding the active, global exploitation of two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products: CVE-2026-88771 and CVE-2026-88772. These flaws, both carrying a CVSS score of 9.5, allow for remote code execution (RCE) and have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, mandating federal civilian agencies to apply fixes by September 30, 2026.
This development is highly significant for any organization utilizing Citrix NetScaler appliances, as the vulnerabilities present a direct and unauthenticated path to compromise. CVE-2026-88771, an improper input validation flaw, is particularly concerning as it can be exploited without authentication and affects default configurations, making a vast number of deployments immediately vulnerable. Successful exploitation grants attackers full control over the gateway, providing direct access to internal corporate networks. CVE-2026-88772, a memory corruption vulnerability, also enables RCE or denial-of-service, though its exploitation complexity is higher and requires the DTLS configuration to be enabled.
The active exploitation of these vulnerabilities aligns with a broader trend of attackers increasingly targeting internet-facing network infrastructure and application delivery controllers as entry points into corporate networks. These devices, often positioned at the perimeter, are critical for business operations but also represent high-value targets due to their privileged network access. The rapid inclusion in CISA's KEV catalog highlights the observed in-the-wild exploitation and the severe risk these vulnerabilities pose, echoing past incidents where critical infrastructure components became targets for sophisticated threat actors. The complexity of updating these systems, which often requires downtime, further complicates the response for many organizations.
In practice, organizations must prioritize immediate patching of all affected Citrix NetScaler ADC and Gateway instances to the versions specified by Citrix. Given the confirmed active exploitation, simply patching might not be enough; organizations should also conduct thorough forensic investigations to determine if their systems have already been compromised. Citrix has provided indicators of compromise (IOCs) through NetScaler Console and additional guidance to assist in this process. It is crucial to preserve forensic evidence before applying updates, as patching could lead to the loss of valuable data for incident response. Furthermore, security teams should review and strengthen network segmentation, access controls, and monitoring capabilities around these critical appliances to limit the blast radius in case of a successful attack and detect any suspicious activity post-patching.
Read original source