CISA Demands Urgent Patching for Critical Citrix NetScaler Zero-Days Under Active Exploitation
The Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a critical directive to U.S. government agencies, mandating immediate action against two actively exploited zero-day vulnerabilities in **Citrix NetScaler** appliances. These flaws, identified as **CVE-2026-88771** and **CVE-2026-88772**, allow unauthenticated attackers to achieve remote code execution, posing a significant threat to organizational security.

**CISA** has ordered U.S. government agencies to secure their systems against attacks leveraging two critical **Citrix NetScaler** vulnerabilities. This urgent directive follows **Citrix's** release of security updates to address the flaws, days after national cybersecurity agencies and IT security teams began privately alerting customers.
### Zero-Days Under Active Attack
**Citrix** confirmed active exploitation of **CVE-2026-88771** and **CVE-2026-88772** in zero-day attacks. Both vulnerabilities enable unauthenticated attackers to gain remote code execution on vulnerable **NetScaler** appliances.
**CVE-2026-88771** impacts all **NetScaler ADC** and **NetScaler Gateway** deployments with default configurations. **CVE-2026-88772** requires **DTLS** to be enabled, which **Citrix** notes is toggled on by default on VPN virtual servers.
"Exploitation of **CVE-2026-88771** and **CVE-2026-88772** on unmitigated **NetScaler** deployments has been observed. **Citrix** strongly urges affected customers to install the relevant updated versions as soon as possible," the company warned in a recent blog post.
### Broader Implications and Vulnerability Scope
**Citrix** highlighted that these vulnerabilities, depending on deployment configurations and enabled features, could lead to remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.
Fixed **NetScaler ADC** and **NetScaler Gateway** versions include:
* **NetScaler ADC** and **Citrix NetScaler Gateway** 14.1-73.37 and later releases
* **NetScaler ADC** and **Citrix NetScaler Gateway** 13.1-64.23 and later releases of 13.1
* **NetScaler ADC** 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
* **NetScaler ADC** 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Customers running **NetScaler** versions 12.1 and 13.0, which have reached end-of-life, are advised to migrate to a supported release immediately.
### Indicators of Compromise and Forensic Warnings
**Citrix** has provided generic Indicators of Compromise (**IoCs**) via **NetScaler Console** to assist security teams in identifying potentially compromised deployments. However, the company cautioned that these **IoCs** might have limited forensic value and may not identify all actual compromises, recommending the retention of experienced forensic investigators.
### Government Mandates and International Warnings
**CISA** has added **CVE-2026-88771** and **CVE-2026-88772** to its **Known Exploited Vulnerabilities (KEV) Catalog**. Federal Civilian Executive Branch (**FCEB**) agencies are mandated to secure all vulnerable **Citrix** appliances by September 30, as per **Binding Operational Directive (BOD) 26-04**.
"Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, **CISA** urges users and administrators to review **Citrix's** advisories," the agency warned. They further advised checking for indications of compromise *before* patching, as updates could lead to a loss of forensic visibility.
**CERT-EU**, the cybersecurity service for European Union institutions, also "strongly" advised EU organizations to "run a compromise assessment on any internet-facing appliance running an affected build."
### A Pattern of Exploitation
These two zero-day flaws are the latest in a series of **Citrix** vulnerabilities actively exploited in the wild this year. Earlier in March, **Citrix** urged patching for **CVE-2026-3055** and **CVE-2026-4368**, which were subsequently abused in attacks. More recently, in early September, attackers began exploiting **CVE-2026-19490**, a **NetScaler** authentication bypass patched in mid-August.
Since November 2021, **CISA** has flagged 26 actively exploited **Citrix** vulnerabilities, with six of these being leveraged by ransomware gangs.
### Internet Exposure
Threat watchdog **Shadowserver** currently tracks over 23,000 **IP** addresses with **NetScaler** fingerprints exposed on the Internet, including nearly 22,000 **NetScaler ADC** appliances and just over 1,500 **Gateway** instances. The actual number of vulnerable, unpatched instances remains undetermined.

*Map of Internet-exposed NetScaler instances (Shadowserver)*