Threat Intelligence

US Cyber Agency Warns of Active Attacks on Critical Citrix NetScaler Flaws

The Hacker News · 28 Sept 2026
Key Takeaway If your business uses Citrix NetScaler ADC or Gateway, check your version against Citrix's patched releases immediately and apply updates without delay, even if it requires scheduling downtime.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities catalog after receiving reports of active exploitation. CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, while CVE-2026-88772 requires DTLS to be enabled, a setting that is turned on by default for VPN virtual servers.

CISA said it has received reports and partner threat intelligence confirming attackers are exploiting these flaws globally. The agency acknowledged that patching NetScaler appliances can be complex and may require downtime, which is why it issued the alert to help organisations assess their exposure and prioritise fixes. Citrix has released patched versions addressing both issues and has made generic indicators of compromise available through NetScaler Console so customers can check whether their systems have been affected.

Organisations that suspect they have been compromised are advised to follow Citrix's recommended remediation steps to secure their environments. US federal agencies have been given until 30 September 2026 to apply the fixes, but any business running affected NetScaler devices should treat this as urgent regardless of that deadline.

Citrix NetScaler CISA vulnerability management active exploitation patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.