Software
CISA orders agencies to patch two Citrix NetScaler flaws by 30 September
CISA added two critical Citrix NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog on Sunday and gave federal agencies until 30 September to patch.
Photo: The Hacker NewsKey points
CISA added two critical Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch them by 30 September.
The Cybersecurity and Infrastructure Security Agency on Sunday added two critical Citrix NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by 30 September. Both flaws allow unauthenticated attackers to gain remote code execution on NetScaler appliances used for application delivery and gateway access.
The order matters because CISA said threat actors are actively exploiting these vulnerabilities globally, and because updating NetScaler appliances can be complex and may require downtime. Federal agencies that miss the 30 September deadline fall out of compliance with Binding Operational Directive 26-04, which sets binding patch deadlines for federal civilian systems when flaws are confirmed under active attack.
What CISA ordered and by when
Citrix published a bulletin on Sunday covering eight common vulnerabilities and exposures. The two worst, CVE-2026-88771 and CVE-2026-88772, carry 9.5 Common Vulnerability Scoring System scores, the rating scale from zero to ten that measures flaw severity. CVE-2026-88771 lets an unauthenticated attacker execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow that can cause remote code execution or denial of service.
Citrix confirmed on Sunday that both vulnerabilities are already under attack and urged customers to patch immediately. The company's warning quoted in its bulletin reads: "Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible." The first flaw hits all NetScaler ADC and Gateway deployments running default configurations.
The second flaw, CVE-2026-88772, requires Datagram Transport Layer Security (DTLS), a protocol that encrypts traffic, to be enabled. Citrix noted that DTLS is toggled on by default on VPN virtual servers, which are the gateways remote workers connect through. A third critical flaw in the same bulletin, CVE-2026-88773, rated 9.3, allows HTTP request smuggling, an attack technique that bypasses security controls installed on front-end servers.
How the flaws are exploited
Three further bugs in the bulletin are 8.8-rated memory overflows that can destabilise NetScaler appliances. Another 8.8-rated bug involves TCP Initial Sequence Number prediction, and a 7.0-rated flaw allows feature policy bypass through improper HTTP URL-based expression usage. Fixed versions include NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later, and 13.1-64.23 and later releases of 13.1.
Threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the internet, including nearly 22,000 NetScaler ADC appliances and just over 1,500 Gateway instances. There is no information on how many of those are honeypots, already patched, or running vulnerable configurations. NetScaler versions 12.1 and 13.0 reached end-of-life and no longer receive security updates, so Citrix advised migrating those appliances.
How many appliances are exposed
CISA urged administrators to check for indications of compromise before patching if possible, and to preserve forensic evidence first, since applying updates may cost forensic visibility. Citrix has shared what it calls generic Indicators of Compromise through NetScaler Console, but warned they "might be of limited forensic value and might fail to identify actual compromises" and advised customers to retain experienced forensic investigators.
CERT-EU, the cybersecurity service for European Union institutions, strongly advised EU organisations to run a compromise assessment on any internet-facing appliance running an affected build. The Dutch National Cyber Security Center reportedly warned Dutch organisations about two critical NetScaler zero-days without CVE identifiers that let threat actors place shellcode directly into memory.
These two flaws follow a run of Citrix NetScaler issues exploited in the wild. In March, Citrix urged admins to patch CVE-2026-3055 and CVE-2026-4368 days before attackers began abusing them. In early September, attackers started exploiting a NetScaler authentication bypass, CVE-2026-19490, that had been patched in mid-August. Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, six of them abused by ransomware gangs.
A Reddit thread carries an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline, a day before Citrix's disclosure. The deadline for federal civilian agencies to secure vulnerable Citrix appliances under Binding Operational Directive 26-04 is 30 September.
Frequently asked questions
Which Citrix NetScaler flaws is CISA warning about?
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. Both are rated critical with 9.5 CVSS scores and allow unauthenticated attackers to gain remote code execution on NetScaler appliances.
When must federal agencies patch the Citrix flaws?
CISA ordered Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by 30 September, as mandated by Binding Operational Directive 26-04.
How many NetScaler appliances are exposed online?
Threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the internet.
How this story was checked
- Fact-checked against 3 cited pages. 68 figures, dates and quotations in this story were found on the pages it cites.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
- thehackernews.comread and checked
- bleepingcomputer.comread and checked
- theregister.comread and checked
Written by Kaer from public reporting. Checked 28 September 2026.


