CISA Flags Actively Exploited Citrix NetScaler Vulnerabilities
CISA has added two new flaws affecting Citrix NetScaler devices to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively exploiting them. CVE-2026-88771 relates to improper input validation, while CVE-2026-88772 involves a memory buffer handling flaw. Both affect Citrix NetScaler, a widely used networking product for load balancing and secure remote access.
While the associated directive requiring rapid patching applies specifically to US federal agencies, CISA encourages all organisations, including those in Australia, to treat KEV listings as a priority signal. Vulnerabilities added to this catalog have documented real-world exploitation, meaning the risk is not theoretical. Businesses running Citrix NetScaler appliances, often used at the network perimeter for secure access, should check vendor advisories and apply available patches without delay, since these devices are frequently targeted as an entry point into corporate networks.
Organisations should also review whether their NetScaler systems were exposed to the internet before patching, as compromise may have already occurred prior to remediation.