Critical Citrix NetScaler Flaws Under Active Attack
CISA adds to critical flaws to KEV catalogue, commands agencies to patch within three days.
The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch two critical Citrix NetScaler vulnerabilities that are being actively exploited in the wild.
The vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalogue on 27th September, with federal agencies given until 30th September to secure affected systems.
In a security update and related blog post published on Sunday, Citrix confirmed that the vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, were being exploited, urging customers to update immediately.
Citrix has released updates for affected versions of NetScaler ADC and NetScaler Gateway.
Vulnerabilities Allow Remote Code Execution
Both flaws can allow remote code execution (RCE), enabling an unauthorised attacker to run commands on vulnerable NetScaler appliances.
CVE-2026-88771 (CVSS score 9.5, Critical) is a pre-authentication remote code execution vulnerability caused by improper input validation. According to Citrix, it affects NetScaler ADC and NetScaler Gateway deployments running in their default configuration.
CVE-2026-88772 (CVSS score 9.5, Critical) is a memory overflow vulnerability that can also allow to remote code execution and, in some circumstances, denial of service. It requires the DTLS protocol to be enabled - a default setting on Citrix VPN virtual servers.
Qualys security research manager Mayuresh Dani described CVE-2026-88771 as allowing "a remote, unauthenticated threat actor to run arbitrary commands. All affected installations in their default configuration are vulnerable.”
The disclosure by Citrix follows reports over recent days by security organisations that previously undisclosed NetScaler vulnerabilities were under attack, including via techniques involving injecting shellcode directly into the memory of a vulnerable appliance.
More than 23,000 internet-facing NetScaler systems are visible online, according to Shadowserver Foundation, as reported by Bleeping Computer.
Mitigation Advice
The most important message for IT leaders is that patching alone may not be enough.
Qualys’ Dani warned that applying updates "does not remove an existing webshell that has been placed on a compromised device".
Therefore, organisations should first check Citrix's indicators of compromise (IOCs), then patch immediately, review internet-facing services, and maintain heightened monitoring of affected appliances.
Citrix advises customers to rotate passwords, API keys, tokens and certificates if compromise is suspected. They should also investigate connected authentication systems and management servers for signs of lateral movement, an, if indication of compromise is found, consider completely rebuilding the appliance.
The company recommends forwarding NetScaler logs to an external logging or SIEM platform, indicating that that attackers can maintain persistence and alter vulnerable devices, said Dani. “Hence, all these devices should be under strict observation for at least 90 days.”
CISA also urged administrators to check for evidence of compromise before patching where possible and seek to preserve forensic evidence, warning that updates may reduce visibility into attacker activity.
Another CitrixBleed?
The latest announcement is inevitably being compared to CitrixBleed, the 2023 NetScaler bug that enabled attackers to bypass MFA and steal authentication tokens and hijack user sessions. That vulnerability was exploited by several groups leading to breaches at organisations including Boeing and China's ICBC bank.
It underlines the continuing risk to internet-facing gateways, VPN appliances and application delivery controllers, which are among the most attractive targets for cybercriminal and state-backed attackers alike.
This article originally appeared on MES Computing's sister site Computing.