Back to Newsroom
Threat Intel

CISA Orders Federal Agencies to Patch Two Exploited Citrix NetScaler Zero-Days by Wednesday

Citrix has confirmed active exploitation of two critical NetScaler ADC and Gateway vulnerabilities that let unauthenticated attackers run code remotely, triggering a hard U.S. government patch deadline and emergency guidance across Europe.

CISA Orders Federal Agencies to Patch Two Exploited Citrix NetScaler Zero-Days by Wednesday

What happened

CISA has ordered U.S. federal civilian agencies to lock down their Citrix NetScaler appliances after confirming active, in-the-wild exploitation of two critical vulnerabilities — CVE-2026-88771 and CVE-2026-88772 — affecting NetScaler ADC and NetScaler Gateway.

Before either flaw had a public CVE identifier, national cybersecurity agencies were already quietly warning organizations. The Dutch National Cyber Security Center reportedly told some operators to physically disconnect vulnerable appliances, since attackers were found placing shellcode directly into memory.

Both bugs let unauthenticated attackers achieve remote code execution, though the conditions differ:

  • CVE-2026-88771 affects every NetScaler ADC and Gateway deployment running a default configuration.
  • CVE-2026-88772 requires DTLS to be enabled — which it is, by default, on VPN virtual servers.

Depending on configuration, affected deployments can also be hit with denial of service, HTTP request smuggling, security-policy bypass, and TCP sequence-number prediction.

CISA has added both CVEs to its Known Exploited Vulnerabilities catalog and, under Binding Operational Directive 26-04, given Federal Civilian Executive Branch agencies until September 30 to secure every vulnerable appliance. CERT-EU has separately urged EU institutions to run a full assessment of any internet-facing appliance on an affected build.

Exposure is not small: threat-monitoring service Shadowserver counts roughly 23,000 internet-facing IP addresses carrying NetScaler fingerprints — close to 22,000 ADC instances and just over 1,500 Gateways — with no visibility into how many are already patched, are honeypots, or remain wide open.

Citrix has released fixed builds and published generic indicators of compromise through NetScaler Console, but it's cautioning customers not to treat a clean IoC scan as proof of safety: the indicators, in Citrix's own words, may carry limited forensic value and can miss real compromises. Organizations that suspect they've already been breached are advised to preserve forensic evidence before applying the update, since patching can wipe out the very artifacts investigators would need. NetScaler versions 12.1 and 13.0 are past end-of-life and won't receive a fix at all — those deployments need to be migrated to a supported release.

Why it matters

Unauthenticated remote code execution on edge VPN and application-delivery appliances is about as bad as exposure gets: this equipment sits directly on the network perimeter, so a successful compromise can hand an attacker a foothold that skips past most internal defenses entirely. It's also not an isolated event. Citrix has had a string of actively exploited NetScaler flaws patched this year — two more in March (CVE-2026-3055 and CVE-2026-4368) and an authentication bypass (CVE-2026-19490) that came under attack in early September, weeks after its mid-August fix. Since 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities overall, six of them tied to ransomware operations.

What to do

  • Inventory every NetScaler ADC and Gateway instance and check its version against Citrix's fixed releases.
  • Patch immediately, prioritizing anything internet-facing.
  • If compromise is even a possibility, capture logs and memory before you patch — the update itself can destroy forensic evidence.
  • Run Citrix's published indicators of compromise through NetScaler Console, but treat a clean result as inconclusive rather than a green light.
  • Migrate any NetScaler 12.1 or 13.0 deployments off end-of-life versions — no patch is coming for them.
  • Map your external exposure (Shadowserver-style scanning helps) and restrict management and VPN interfaces wherever you can.
  • Bring in experienced incident-response and forensics support the moment you see any sign of compromise.
SHARE