HomeSecurityCitrix NetScaler - CISA: Vulnerability fixes until September 30

Citrix NetScaler – CISA: Vulnerability patching until September 30

Two critical vulnerabilities in Citrix NetScaler are causing alarm for government and corporate networks , as they have been confirmed to be exploited by malicious users in real-world cyberattacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to take immediate protective measures, setting a deadline of September 30, 2026.

Citrix NetScaler - CISA

The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, affect NetScaler ADC and NetScaler Gateway, which are widely used to securely access enterprise applications and connect remote workers to corporate networks.

Citrix has already released patches and urges administrators to install them without delay. The fact that the vulnerabilities are being exploited before affected systems are fully patched increases the need for immediate assessment of the exposure and potential compromise.

See also: CVE-2026-100899: SQL injection in DevaslanPHP project-management

Two zero-day vulnerabilities with remote code execution capability

The two security vulnerabilities are considered particularly serious, as they could allow unauthenticated attackers to remotely execute code on vulnerable NetScaler devices, under the corresponding exploit conditions.

The first vulnerability, CVE-2026-88771, affects NetScaler ADC and NetScaler Gateway using default settings. The second, CVE-2026-88772, affects systems with DTLS enabled. Citrix notes that DTLS is enabled by default on VPN virtual servers, making it necessary to check these configurations.

A successful attack could give attackers the ability to execute commands on systems that act as gateways to corporate infrastructure. Depending on the configuration and available permissions, this could be a stepping stone to further network penetration, information theft, or service disruption.

Citrix confirmed the active exploitation of the two vulnerabilities and recommended that its customers apply the available updates as soon as possible.

Citrix NetScaler: What other risks are associated with the vulnerabilities?

Beyond remote code execution, the company described other categories of problems that may be related to the affected functions and individual system configurations.

These include DoS attacks, HTTP request smuggling techniques, bypassing security policies, and the ability to predict the initial TCP sequence number under certain conditions.

HTTP request smuggling is a technique in which an attacker attempts to cause HTTP requests to be interpreted differently by successive systems processing the same traffic. In some environments, such discrepancies can be exploited to bypass controls or access information that should not be available.

The severity of each case depends on operating conditions, enabled services, and network architecture. For this reason, organizations should not limit themselves to a general risk assessment, but should specifically check the software versions and settings of their devices.

See also: CVE-2026-100884: Vulnerability in Krayin CRM fixed in 2.2.6

Citrix NetScaler - CISA: Vulnerability patching until September 30

CISA adds vulnerabilities to KEV list

On Sunday, CISA added the two vulnerabilities to the Known Exploited Vulnerabilities (KEV) list, which includes security weaknesses for which there is evidence of active exploitation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Under Business Commitment Directive BOD 26-04, US federal agencies are required to protect vulnerable devices by September 30th.

The deadline is specific to specific federal agencies and is not automatically a binding deadline for every private company. However, inclusion on the KEV list is a significant indication that addressing vulnerabilities should become a high priority for other organizations that use the affected technologies.

Similar warnings were issued in Europe. CERT-EU recommended that European Union organizations assess whether devices exposed to the internet and running affected software versions have been compromised.

More than 23,000 exposed IP addresses

The extent of the potential exposure is of additional concern. According to data from threat monitoring Shadowserver, more than 23,000 IP addresses display characteristics that point to NetScaler appliances accessible over the internet.

Of these, nearly 22,000 correspond to NetScaler ADC appliances, while more than 1,500 are related to Gateway installations.

These numbers do not prove that all devices are vulnerable or have been compromised. Some may be running patched versions, others may be using more secure settings, and the measurements may include monitoring systems or honeypots created to record attacks.

However, the presence of thousands of devices online underscores the importance of rapid inventory of corporate infrastructure. A device that has been forgotten in an older installation or is managed by a different IT team can remain exposed even after the rest of the systems have been updated.

Installing patches is not always enough

Citrix has made generic Indicators of Compromise (IoCs) available through the NetScaler Console to help administrators identify suspicious activity

However, the company cautioned that these indicators may have limited value in incident investigation and may not detect every actual breach, so the absence of known indicators does not necessarily mean a system is clean.

CISA recommends, where possible, checking for evidence of a breach before applying updates. If an attack is suspected, organizations should retain logs and other digital evidence, as installing updates or rebooting systems can impact the ability to investigate later.

See also: CVE-2026-101065: Critical flaw in Obot leaves Docker unchecked

The correct response therefore requires a combination of immediate remediation, checking log files, investigating suspicious connections and assessing possible lateral movement of the attackers. In case of indications of a breach, it is advisable to enlist the help of specialized digital forensics teams.

Citrix NetScaler - CISA: Vulnerability patching until September 30

Citrix devices are a recurring target

These vulnerabilities add to a series of Citrix security issues that have been exploited in real-world attacks throughout 2026.

In March, administrators were asked to install fixes for CVE-2026-3055 and CVE-2026-4368, while in early September, an exploit for CVE-2026-19490, which involved an authentication bypass and was fixed in an update released in August.

Additionally, as of November 2021, CISA has documented 26 Citrix vulnerabilities that have been actively exploited, including six used by ransomware groups.

For businesses, the key takeaway is that remote access gateways require ongoing monitoring, regular updates, and strict control of exposed services. Prompt installation of available patches, coupled with a thorough investigation of a potential breach, is a critical step in mitigating risk.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS