Skip to main content
Emerging Threats

CISA Warns of Global Exploitation of Citrix NetScaler Flaws

Technicians work in a daylight-flooded network operations center with rows of equipment and server racks.

"CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said.

CVE-2026-88771 and CVE-2026-88772: scope, severity, and impact

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaws are identified as:

  • CVE-2026-88771 (CVSS score: 9.5) — an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
  • CVE-2026-88772 (CVSS score: 9.5) — an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow remote code execution or denial-of-service.

According to the advisory language, CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments. CVE-2026-88772 requires a specific configuration to be enabled: the DTLS configuration on NetScaler ADC or NetScaler Gateway.

DTLS configuration and VPN virtual servers: a configuration detail that changes exposure

CISA’s notice highlights that DTLS is turned on by default on VPN virtual servers, and provides the relevant configuration example:

  • add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE

Because that DTLS setting is enabled by default for VPN virtual servers, many installations that expose VPN functionality may be exposed to CVE-2026-88772 unless the DTLS option has been disabled or otherwise mitigated.

Available fixes: patched Citrix NetScaler versions

Citrix has released firmware updates that address both issues. The fixes are included in the following releases and later:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

CISA noted that updating NetScaler appliances "can be complex and may require downtime," and said it issued the alert to help organizations assess exposure, prioritize mitigation, and incorporate these vulnerabilities into risk-management activities.

Citrix guidance and indicators of compromise via NetScaler Console

Citrix has made generic indicators of compromise (IoCs) available through NetScaler Console to help customers determine whether their deployments have been impacted. If a compromise is suspected, Citrix recommends customers take these steps:

  • Preserve evidence of the NetScaler ADC VPX instance.
  • Isolate the device.
  • Revoke credentials and access.
  • Investigate all servers and systems that the NetScaler ADC had connected to for any signs of further compromise.
  • Rebuild and update the firmware to the latest version.
  • Rotate all local account passwords, Key Encryption Keys (KEK), and replace all restored SSL certificates if restoring from a known good NetScaler backup.
  • Harden the device in line with best practices.

What this means for FCEB agencies, enterprise administrators, and security teams

  • FCEB agencies: Federal Civilian Executive Branch agencies "have been given time until September 30, 2026, to apply the fixes," creating a fixed compliance window tied directly to the presence of active exploitation reported by CISA.
  • Enterprise administrators: Organizations running NetScaler ADC or NetScaler Gateway must inventory deployments, confirm whether DTLS is enabled on VPN virtual servers, consult the listed patched releases, and weigh potential downtime against the active exploitation risk.
  • Security teams: Teams should use the IoCs available through NetScaler Console, preserve evidence and isolate suspected devices, and follow the full containment and recovery steps Citrix provided to investigate lateral movement and to rebuild affected systems.

The combination of high CVSS scores, active exploitation confirmed by CISA, and the practical complexity of updating appliances frames this as an urgent operational problem: apply the listed firmware updates where possible, use the IoCs to hunt for compromise, and follow Citrix's containment checklist if intrusion is suspected. CISA’s alert is explicit that organizations must prioritize mitigation and fold these vulnerabilities into risk-management decisions in the near term.

Original story — The Hacker News