US Cyber Agency Warns of Active Attacks on Critical Citrix NetScaler Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog after receiving reports of active exploitation. CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, while CVE-2026-88772 requires DTLS to be enabled, a setting that is turned on by default for VPN virtual servers.
CISA said it has received reports and partner threat intelligence confirming attackers are exploiting these flaws globally. The agency acknowledged that patching NetScaler appliances can be complex and may require downtime, which is why it issued the alert to help organisations assess their exposure and prioritise fixes. Citrix has released patched versions addressing both issues and has made generic indicators of compromise available through NetScaler Console so customers can check whether their systems have been affected.
Organisations that suspect they have been compromised are advised to follow Citrix's recommended remediation steps to secure their environments. US federal agencies have been given until 30 September 2026 to apply the fixes, but any business running affected NetScaler devices should treat this as urgent regardless of that deadline.