CISA Warns of Active Exploitation in Citrix NetScaler Vulnerabilities
The **Cybersecurity and Infrastructure Security Agency (CISA)** has issued an urgent alert regarding eight newly disclosed vulnerabilities affecting **Citrix NetScaler ADC** and **Citrix NetScaler Gateway** products. Two critical zero-day vulnerabilities, **CVE-2026-88771** and **CVE-2026-88772**, are already being actively exploited globally, enabling remote code execution.
CISA is amplifying **Citrix's** disclosure of eight new vulnerabilities impacting their **NetScaler ADC** and **NetScaler Gateway** products. These include **CVE-2026-88771**, **CVE-2026-88772**, **CVE-2026-88773**, **CVE-2026-88774**, **CVE-2026-88775**, **CVE-2026-88776**, **CVE-2026-88777**, and **CVE-2026-88778**.
### Critical Exploitation Underway
Of particular concern are **CVE-2026-88771** and **CVE-2026-88772**, which CISA has added to its **Known Exploited Vulnerabilities (KEV) Catalog**. Both are critical, zero-day vulnerabilities capable of independently facilitating remote code execution. CISA has confirmed, through internal reports and partner threat intelligence, that malicious actors are actively exploiting these vulnerabilities on a global scale.
### Prioritizing Mitigation and Risk Management
Recognizing the complexity and potential downtime associated with updating **Citrix NetScaler** deployments, CISA has issued this alert to assist organizations in assessing their exposure, prioritizing mitigation efforts, and integrating these vulnerabilities into their existing risk management frameworks.
Given the severe potential consequences of successful exploitation and the confirmed active exploitation of at least some of these vulnerabilities, CISA strongly urges users and administrators to review **Citrix's** advisories immediately.
### Pre-Patch Compromise Detection and Forensic Preservation
Organizations are encouraged to check for indicators of compromise (IoCs) *before* applying patches. **Citrix** has made IoCs available via **NetScaler Console** and provided additional guidance in their recent publication, *Security Bulletin for CVE-2026-88771 through CVE-2026-88778*, to aid in assessing potential compromise.
Crucially, if an organization suspects compromise, it is vital to preserve forensic evidence prior to applying updates, as patching may lead to the loss of valuable forensic visibility.
### Key Resources:
* [Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778 - Security Updates - Citrix Community](https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/?utm_id=cid2026-0806&utm_source=facebook&utm_medium=social%20media%20organic&utm_campaign=citrix%20organic&utm_content=1790523126)
* [Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096)
* [Steps to Take if NetScaler ADC is Suspected to be Compromised](https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html)