AI Weekly Malaysia

Back to items Summaries

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

ID
29246
Status
summarized
Published
28 Sep 2026, 3:21 PM
Fetched
28 Sep 2026, 6:28 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
28 Sep 2026, 6:29 PM
Tags
Audience
developerssaas_startup_founders

What happened

On Sunday, CISA added two critical Citrix NetScaler ADC/Gateway flaws to its Known Exploited Vulnerabilities catalog, citing partner threat intelligence confirming active global exploitation. CVE-2026-88771 (CVSS 9.5) is improper input validation allowing unauthenticated arbitrary command execution and affects all ADC and Gateway deployments; CVE-2026-88772 (CVSS 9.5) is a memory buffer bounds issue enabling RCE or denial-of-service, and requires DTLS to be enabled — which is on by default on VPN virtual servers. Fixes ship in NetScaler ADC/Gateway 14.1-73.37 and 13.1-64.23 (plus FIPS/NDcPP 13.1.37.279 and 14.1-73.37 FIPS), and Citrix is publishing generic IoCs through NetScaler Console.

Why it matters

This only changes your week if your organisation terminates remote access through NetScaler ADC or Gateway — then the remedy is a version upgrade to 14.1-73.37 or 13.1-64.23, not a config toggle, and CISA itself warns the update is complex and may need downtime, so book the maintenance window now rather than at the next patch cycle. If a compromise is suspected, the stated sequence is preserve the VPX instance evidence, isolate the device, revoke credentials and access, then investigate every system the appliance connected to before rebuilding. If you don't run NetScaler, there is nothing actionable here for you.

Discussion angle

Ask who in the room can actually name the appliances terminating their company VPN and who owns patching them — CISA's own note that NetScaler updates are complex and downtime-prone is the real lesson about unowned internet-facing edge gear.

Top