Summary Points
- The U.S. CISA has added two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) to its KEV catalog, actively exploited globally, with scores of 9.5 for remote code execution risks.
- Both flaws impact all NetScaler ADC and Gateway versions, with updates available in specific later releases, and require urgent mitigation due to active exploitation reports.
- Threat actors exploited these vulnerabilities using pre-authentication commands, with over 50,000 potentially vulnerable devices identified, and active attempts observed since September 24, 2026.
- Organizations should follow recommended steps—such as isolating affected devices, revoking access, updating firmware, and monitoring for IoCs—to secure impacted environments amidst ongoing threats.
Critical Flaws in Citrix NetScaler Devices Exploited Worldwide
Recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced alarming news. It added two serious vulnerabilities in Citrix NetScaler ADC and Gateway to its list of known exploited flaws. This move follows reports that cyber attackers actively target these weaknesses globally. As a result, organizations worldwide must pay close attention to these security risks.
These vulnerabilities are particularly dangerous because they allow hackers to take control of affected systems. One flaw, identified as CVE-2026-88771, scores a high 9.5 out of 10 for severity. It could let unauthorized users run any command they want. The second flaw, CVE-2026-88772, also scores 9.5 and involves remote code execution or denial-of-service. This second problem occurs if the default DTLS setting on the device is enabled.
Not all NetScaler setups are affected equally. The first flaw impacts all deployments, while the second mainly targets those with DTLS enabled—settings turned on by default in many virtual private network configurations. Fortunately, Citrix released updates to fix these issues. Users of specific versions of the software should upgrade to the latest releases to secure their systems.
CISA underscores the urgency of this matter. Because updating these devices can be complicated and may cause downtime, the agency advises organizations to act quickly. They should evaluate their exposure and include these vulnerabilities in their risk management plans. Additionally, Citrix has provided tools to help identify if systems have been compromised, including indicators of attack.
Experts warn that threat actors are not only exploiting these flaws but also attempting to hide their activities. For example, attackers have tried to modify web server files to insert malicious code and evade detection. In one case, an attacker used a webshell to gain persistent access, illustrating the seriousness of the threat.
Given the widespread use of Citrix NetScaler devices, these vulnerabilities pose significant security challenges. Organizations must act now by applying necessary updates, monitoring systems closely, and following best security practices. The goal remains protecting critical data and maintaining trust in digital infrastructures as technology continues to evolve and human progress advances.
Continue Your Tech Journey
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
CyberAttacks-V1
