CISA Orders Federal Agencies to Patch Exploited Citrix NetScaler Flaws

CISA orders U.S. federal agencies over the weekend to secure their systems against two critical Citrix NetScaler vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, with a patch deadline of Wednesday. The flaws allow unauthenticated attackers to gain remote code execution on vulnerable NetScaler ADC and NetScaler Gateway appliances. Citrix confirms active zero-day exploitation and urges all customers to apply fixes immediately.

The first flaw affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled, which is on by default for VPN virtual servers. Citrix notes the issues can also enable denial of service, HTTP request smuggling, policy bypass, and TCP sequence number prediction under specific conditions. The Dutch NCSC previously warned organizations about the zero-days, which allow attackers to inject shellcode directly into memory.

Patched releases include NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, plus corresponding FIPS and NDcPP builds. Citrix warns that NetScaler versions 12.1 and 13.0 have reached end-of-life and receive no security updates, advising customers on these versions to migrate to supported releases as soon as possible.

Read More at the original source →