CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
thehackernews.com Sep 28, 2026

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

AI-summarised brief · reviewed before publication

The U.S. Cybersecurity and Infrastructure Security Agency added two critical Citrix NetScaler ADC and Gateway vulnerabilities, CVE‑2026‑88771 and CVE‑2026‑88772, to its Known Exploited Vulnerabilities catalog after confirming active exploitation worldwide. CVE‑2026‑88771 affects all NetScaler ADC and Gateway deployments, while CVE‑2026‑88772 requires the DTLS configuration, which is enabled by default on VPN virtual servers. Citrix has released patches for versions below the affected releases and provided indicators of compromise. Federal agencies must apply fixes by September 30, 2026.

💡 Why It Matters

  • · The vulnerabilities expose a broad range of enterprise networks to remote code execution, forcing organizations to prioritize patching amid complex deployment environments.
  • · The alert underscores the urgency of addressing zero‑day exploits that can be leveraged by attackers to gain persistent, high‑level access.