U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
CISA added two actively exploited Citrix NetScaler zero-days to the KEV catalog.
CISA added CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, to the Known Exploited Vulnerabilities catalog after confirming active global exploitation of Citrix NetScaler ADC and Gateway. CVE-2026-88771 is unauthenticated remote code execution from improper input validation and affects default configurations. CVE-2026-88772 is a CWE-119 memory buffer overflow that can cause remote code execution or denial of service when DTLS is enabled, which is default on VPN virtual servers. Citrix fixed both in 14.1-73.37, 13.1-64.23, and corresponding FIPS builds; federal agencies must remediate by September 30, 2026.