CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- ID
- 29246
- Status
- summarized
- Published
- 28 Sep 2026, 3:21 PM
- Fetched
- 28 Sep 2026, 6:28 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 28 Sep 2026, 6:29 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
On Sunday, CISA added two critical Citrix NetScaler ADC/Gateway flaws to its Known Exploited Vulnerabilities catalog, citing partner threat intelligence confirming active global exploitation. CVE-2026-88771 (CVSS 9.5) is improper input validation allowing unauthenticated arbitrary command execution and affects all ADC and Gateway deployments; CVE-2026-88772 (CVSS 9.5) is a memory buffer bounds issue enabling RCE or denial-of-service, and requires DTLS to be enabled — which is on by default on VPN virtual servers. Fixes ship in NetScaler ADC/Gateway 14.1-73.37 and 13.1-64.23 (plus FIPS/NDcPP 13.1.37.279 and 14.1-73.37 FIPS), and Citrix is publishing generic IoCs through NetScaler Console.
Why it matters
This only changes your week if your organisation terminates remote access through NetScaler ADC or Gateway — then the remedy is a version upgrade to 14.1-73.37 or 13.1-64.23, not a config toggle, and CISA itself warns the update is complex and may need downtime, so book the maintenance window now rather than at the next patch cycle. If a compromise is suspected, the stated sequence is preserve the VPX instance evidence, isolate the device, revoke credentials and access, then investigate every system the appliance connected to before rebuilding. If you don't run NetScaler, there is nothing actionable here for you.
Discussion angle
Ask who in the room can actually name the appliances terminating their company VPN and who owns patching them — CISA's own note that NetScaler updates are complex and downtime-prone is the real lesson about unowned internet-facing edge gear.