The Cybersecurity and Infrastructure Security Agency over the weekend directed U.S. government agencies to protect their systems from attacks that exploit two critical Citrix NetScaler vulnerabilities. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog on Sunday and ordered Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by September 30 under Binding Operational Directive 26-04. The order followed Citrix's confirmation that day of active exploitation of both flaws in zero-day attacks.
Citrix released security updates for the two flaws after national cybersecurity agencies, IT suppliers and security teams began privately warning Citrix customers to shut down their NetScaler appliances. The Dutch National Cyber Security Center reportedly alerted organizations in the Netherlands to two critical NetScaler zero-days without CVE IDs that let threat actors place shellcode directly into memory. Both vulnerabilities allow unauthenticated attackers to achieve remote code execution on affected NetScaler appliances.
The first flaw affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled; Citrix noted that DTLS is toggled on by default on VPN virtual servers. In a Sunday blog post carrying a noindex meta tag, Citrix said exploitation of both CVEs had been observed on unmitigated NetScaler deployments and strongly urged affected customers to install the relevant updated versions as soon as possible. The company said the vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass and TCP initial sequence number prediction under specific conditions.
Citrix has shared what it describes as generic Indicators of Compromise through NetScaler Console to help security teams identify deployments that may already be compromised. It warned that these IoCs might be of limited forensic value and might fail to identify actual compromises, and advised customers to retain experienced forensic investigators. CISA likewise encouraged users to check for indication of compromise before patching and said organizations that suspect compromise should preserve forensic evidence before applying updates, since updates may result in loss of forensic visibility.
CERT-EU, the cybersecurity service for all European Union institutions, bodies, offices and agencies, also strongly advised EU organizations to run a compromise assessment on any internet-facing appliance running an affected build. Threat watchdog Shadowserver currently tracks more than 23,000 IP addresses with NetScaler fingerprints exposed on the Internet, including nearly 22,000 NetScaler ADC appliances and just over 1,500 Gateway instances. There is no information on how many are honeypots, have already been patched, or have vulnerable configurations.
The two flaws are the latest in a series of Citrix vulnerabilities attackers have exploited in the wild since the start of the year. In March, Citrix urged admins to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, days before threat actors began abusing them in attacks. In early September, attackers began exploiting a NetScaler authentication bypass, CVE-2026-19490, that was patched in mid-August.
Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, including six abused by ransomware gangs. CISA urged users and administrators to review Citrix's advisories, citing the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities.
More cybersecurity news from TechManNews.






