Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Cyber

BreakingCISA Flags Two Exploited Citrix NetScaler Zero-Days in KEV List

CISA said threat actors are exploiting two critical NetScaler ADC and Gateway flaws globally, among eight vulnerabilities disclosed by Citrix.

CISA Flags Two Exploited Citrix NetScaler Zero-Days in KEV List. Source: CISA

The US Cybersecurity and Infrastructure Security Agency said on September 27, 2026 that it is amplifying Citrix's disclosure of eight new vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway, and has added two of them to its Known Exploited Vulnerabilities Catalog after confirming active exploitation.

What CISA disclosed

The alert covers eight CVEs affecting Citrix NetScaler ADC and Citrix NetScaler Gateway: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777 and CVE-2026-88778.

CISA said it added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. According to the agency, both are critical, zero-day vulnerabilities that can independently enable remote code execution.

CISA said it has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

Why the agency issued an alert

CISA said it published the alert because updating Citrix NetScaler appliances can be complex and may require downtime, and it wants organizations to assess exposure, prioritize mitigation and account for the vulnerabilities in their risk-management activities.

Citing the potential consequences of successful exploitation and ongoing exploitation of at least some of the flaws, the agency urged users and administrators to review Citrix's advisories.

Check for compromise before patching

CISA encouraged organizations, where possible, to check for indications of compromise before applying patches. The agency said Citrix has made indicators of compromise available through NetScaler Console and published additional guidance in its security bulletin covering CVE-2026-88771 through CVE-2026-88778.

Organizations that suspect a compromise should preserve forensic evidence before applying updates, CISA said, because updates may result in loss of forensic visibility. Citrix has also published steps to take if a NetScaler ADC appliance is suspected to be compromised, according to the alert.

CISA added a standard disclaimer that references to commercial products do not constitute endorsement by the agency.

What to do

  • Review Citrix's advisories, including the security bulletin covering CVE-2026-88771 through CVE-2026-88778.
  • Where possible, check appliances for indications of compromise before patching, using the indicators of compromise Citrix makes available through NetScaler Console.
  • If you suspect a compromise, preserve forensic evidence before applying updates, since patching may cause loss of forensic visibility.
  • Assess your exposure, prioritize mitigation and factor these vulnerabilities into risk-management planning, allowing for the downtime NetScaler updates may require.
  • Follow Citrix's published steps for NetScaler ADC appliances suspected to be compromised.
Key facts and where they come from
  • CISA amplified Citrix's disclosure of eight vulnerabilities in NetScaler ADC and Gateway.
    CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products
  • Two of the CVEs were added to the KEV Catalog.
    CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog.
  • Both KEV-listed flaws are critical zero-days enabling remote code execution.
    Both are critical, zero-day vulnerabilities that can independently enable remote code execution.
  • CISA said exploitation is occurring globally.
    CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
  • Patching may destroy forensic evidence.
    it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility
  • Citrix provides indicators of compromise via NetScaler Console.
    Citrix has made indicators of compromise available through NetScaler Console

Read the original from CISA →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Cyber