On September 27, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the inclusion of two significant vulnerabilities affecting Citrix NetScaler ADC and Gateway in its Known Exploited Vulnerabilities (KEV) catalog. This decision was influenced by credible reports indicating active exploitation of these flaws in the wild. The vulnerabilities in question—CVE-2026-88771 and CVE-2026-88772—carry a notably high CVSS score of 9.5, underscoring their critical nature.
CVE-2026-88771 is characterized as an improper input validation vulnerability, which could allow unauthenticated attackers to execute arbitrary commands on affected systems. CVE-2026-88772, meanwhile, involves an improper restriction of operations within a memory buffer, heightening the risk of remote code execution or denial-of-service incidents. While the first vulnerability impacts all deployments of NetScaler ADC and Gateway, CVE-2026-88772 specifically requires the DTLS configuration to be enabled, a setting typically activated by default on VPN virtual servers.
According to CISA, both vulnerabilities have demonstrated active exploitation globally. In light of this threat, the agency emphasizes the importance of organizations evaluating their exposure and prioritizing mitigation efforts as part of their risk management processes. The agency has advised that due to the complexities associated with updating Citrix NetScaler appliances—often requiring system downtime—quick action is essential.
Citrix has addressed these vulnerabilities in several versions of their software, including Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later, as well as 13.1-64.23 and subsequent updates, both in standard and FIPS-compliant versions. The company has also provided generic indicators of compromise (IoCs) via the NetScaler Console, assisting organizations in determining if their systems have been compromised.
In a proactive stance, organizations that suspect they may be affected are advised to take immediate action to secure their environments. This includes preserving evidence of any compromised NetScaler ADC instances, isolating impacted devices, revoking credentials, and investigating connected systems for further compromise. Additionally, they should rebuild systems and update firmware to the latest secure version.
Recent cybersecurity observations highlight that more than 50,000 instances of Citrix NetScaler devices remain publicly exposed and potentially vulnerable to exploitation. Reports from Palo Alto Networks Unit 42 have recorded attempts to exploit these vulnerabilities, with malicious actors utilizing various techniques such as pre-authentication requests to manipulate input data, thereby achieving unauthorized command execution.
From a tactical perspective, the vulnerabilities align with various MITRE ATT&CK techniques related to initial access, leveraging improper input validation for exploitation, as well as techniques for privilege escalation through unverified command execution. Given the escalating sophistication of cyber threats, it is vital for organizations, particularly in the U.S., to remain vigilant and proactive in applying patches and securing their infrastructure against these emerging risks.
In closing, CISA has extended an urgent notice for Federal Civilian Executive Branch agencies, mandating remediation efforts be completed by September 30, 2026, amid reports of ongoing exploitations. As cyber threats become increasingly prevalent, business owners must prioritize cybersecurity to protect their operations and mitigate risks associated with such vulnerabilities.