CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
CISA added two actively exploited Citrix NetScaler zero-days enabling unauthenticated remote code execution to KEV.
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on September 27, 2026, after confirming active exploitation against Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-88771 is an improper-input-validation flaw that lets an unauthenticated remote attacker execute arbitrary commands. CVE-2026-88772 is a CWE-119 memory-buffer flaw that can lead to remote code execution or denial of service. Under BOD 26-04, federal civilian agencies must apply mitigations by September 30, 2026. CISA did not name attackers, targets, or ransomware use, and it requires forensic triage rather than patching alone.
- CVE-2026-88771 allows unauthenticated remote command execution
- CVE-2026-88772 can enable remote code execution or denial of service
- Both were added to CISA KEV on September 27, 2026
- Federal agencies must mitigate by September 30, 2026
- CISA requires forensic triage because exploitation may already have occurred
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article439 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence showed they were being actively exploited in attacks.
The flaws affect Citrix NetScaler ADC and NetScaler Gateway appliances. They could allow unauthenticated attackers to take control of vulnerable systems remotely.
Tracked as CVE-2026-88771 and CVE-2026-88772, the vulnerabilities were added to CISA’s KEV catalog on September 27, 2026. Federal civilian executive branch agencies must apply vendor-recommended mitigations by September 30, 2026, under Binding Operational Directive 26-04.
CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated remote attacker could exploit the flaw to execute arbitrary commands on an affected appliance.
This creates a high-risk situation because internet-facing NetScaler devices often serve as entry points for remote access, application delivery, and virtual private network services.
The second flaw, CVE-2026-88772, is classified as an improper restriction of operations within the bounds of a memory buffer vulnerability. Successful exploitation could enable remote code execution or cause a denial-of-service condition.
Citrix NetScaler 0-Day RCE Vulnerabilities Exploited
Both vulnerabilities are associated with CWE-119, a category covering memory safety weaknesses that can enable attackers to manipulate program behavior.
CISA confirmed both flaws are exploited in the wild but has not identified the attackers, targets, campaigns, or any ransomware use.
Organizations running Citrix NetScaler ADC or NetScaler Gateway should immediately identify exposed appliances, review Citrix’s security guidance, and apply available patches or mitigations.
Security teams should not assume that patching alone is sufficient where exploitation may already have occurred. CISA requires forensic triage for both vulnerabilities, indicating that affected organizations should investigate systems for signs of compromise before returning them to normal operation.
Defenders should review authentication activity, administrator account changes, configuration modifications, unusual command execution, unexpected outbound network connections, and web-access logs associated with NetScaler appliances.
Organizations should also check whether the devices are exposed directly to the internet and restrict unnecessary management interfaces.
Where mitigations are unavailable, CISA advises organizations to discontinue use of the affected product. Cloud-service stakeholders must also follow applicable BOD 26-04 guidance and assess whether internet-exposed assets meet required patching timelines.
The warning highlights the continued risk posed by edge infrastructure. A compromised NetScaler appliance can provide attackers with a foothold inside an organization while bypassing many traditional endpoint controls.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.