CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence showed they were being actively exploited in attacks.

The flaws affect Citrix NetScaler ADC and NetScaler Gateway appliances. They could allow unauthenticated attackers to take control of vulnerable systems remotely.

Tracked as CVE-2026-88771 and CVE-2026-88772, the vulnerabilities were added to CISA’s KEV catalog on September 27, 2026. Federal civilian executive branch agencies must apply vendor-recommended mitigations by September 30, 2026, under Binding Operational Directive 26-04.

CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated remote attacker could exploit the flaw to execute arbitrary commands on an affected appliance.

This creates a high-risk situation because internet-facing NetScaler devices often serve as entry points for remote access, application delivery, and virtual private network services.

The second flaw, CVE-2026-88772, is classified as an improper restriction of operations within the bounds of a memory buffer vulnerability. Successful exploitation could enable remote code execution or cause a denial-of-service condition.

Citrix NetScaler 0-Day RCE Vulnerabilities Exploited

Both vulnerabilities are associated with CWE-119, a category covering memory safety weaknesses that can enable attackers to manipulate program behavior.

CISA confirmed both flaws are exploited in the wild but has not identified the attackers, targets, campaigns, or any ransomware use.

Organizations running Citrix NetScaler ADC or NetScaler Gateway should immediately identify exposed appliances, review Citrix’s security guidance, and apply available patches or mitigations.

Security teams should not assume that patching alone is sufficient where exploitation may already have occurred. CISA requires forensic triage for both vulnerabilities, indicating that affected organizations should investigate systems for signs of compromise before returning them to normal operation.

Defenders should review authentication activity, administrator account changes, configuration modifications, unusual command execution, unexpected outbound network connections, and web-access logs associated with NetScaler appliances.

Organizations should also check whether the devices are exposed directly to the internet and restrict unnecessary management interfaces.

Where mitigations are unavailable, CISA advises organizations to discontinue use of the affected product. Cloud-service stakeholders must also follow applicable BOD 26-04 guidance and assess whether internet-exposed assets meet required patching timelines.

The warning highlights the continued risk posed by edge infrastructure. A compromised NetScaler appliance can provide attackers with a foothold inside an organization while bypassing many traditional endpoint controls.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks appeared first on Cyber Security News.