BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 28, 2026 · 3 min read · Original story

CISA orders feds to patch exploited Citrix flaws by Wednesday

CISA orders feds to patch exploited Citrix flaws by Wednesday

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.

Citrix released security updates to address the flaws (tracked as CVE-2026-88771 and CVE-2026-88772) days after national cybersecurity agencies, IT suppliers, and security teams began privately contacting Citrix customers and advising them to shut down their NetScaler appliances.

For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.

On Sunday, Citrix confirmed active exploitation of the two vulnerabilities in zero-day attacks and urged customers to patch their systems immediately.

Both flaws allow unauthenticated attackers to gain remote code execution on vulnerable NetScaler appliances. The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers).

"Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible," the company warned in a Sunday blog post that has a 'noindex' meta tag which tells search engines not to index the page.

"These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions."

Fixed NetScaler ADC and NetScaler Gateway versions include:

  • NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Because NetScaler versions 12.1 and 13.0 have reached end-of-life and no longer receive security updates, the company advised customers to migrate appliances running these versions to a supported release.

Citrix has also shared what it describes as "generic Indicators of Compromise" through NetScaler Console to help security teams identify NetScaler deployments that may have already been compromised. However, it also warned that these IoCs "might be of limited forensic value and might fail to identify actual compromises" and advised customers "to retain the services of experienced forensic investigators."

Currently, threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the Internet (including nearly 22,000 NetScaler ADC appliances and just over 1,500 Gateway instances). However, there is no information on how many are honeypots, have already been patched, or have vulnerable configurations.

Map of Internet-exposed NetScaler instances (Shadowserver)

​​​On Sunday, CISA also added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by Binding Operational Directive (BOD) 26-04.

"Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix's advisories," the cybersecurity agency warned.

"If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility."

CERT-EU, the cybersecurity service for all European Union institutions, bodies, offices, and agencies (including the European Commission, the European Parliament, and the European Council), also "strongly" advised EU organizations to "run a compromise assessment on any internet-facing appliance running an affected build."

These two flaws are just the latest of several other Citrix vulnerabilities that attackers have exploited in the wild since the start of the year.

In March, Citrix urged admins to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them in attacks. More recently, in early September, attackers began exploiting a NetScaler authentication bypass (CVE-2026-19490) patched in mid-August.

Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, including six abused by ransomware gangs.

References in this story

  1. NVD - Home nvd.nist.gov
  2. NVD - Home nvd.nist.gov
  3. Citrix confirms two NetScaler RCE zero-days exploited in attacks www.bleepingcomputer.com Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the…
  4. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  5. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  6. CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA www.cisa.gov
  7. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
  8. Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway | CISA www.cisa.gov
  9. Critical Vulnerabilities in Citrix NetScaler ADC and Gateway cert.europa.eu Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
  10. Citrix urges admins to patch NetScaler flaws as soon as possible www.bleepingcomputer.com Citrix has patched two NetScaler ADC and NetScaler Gateway vulnerabilities, one of which is very similar to the CitrixBleed and CitrixBleed2 flaws exploited in zero-day attacks in recent years.
  11. NVD - CVE-2026-3055 nvd.nist.gov
  12. NVD - CVE-2026-4368 nvd.nist.gov
  13. Critical Citrix NetScaler memory flaw actively exploited in attacks www.bleepingcomputer.com Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data.
  14. Critical Citrix NetScaler auth bypass now leveraged in attacks www.bleepingcomputer.com Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
  15. NVD - CVE-2026-19490 nvd.nist.gov
  16. Citrix urges admins to patch new NetScaler flaws as soon as possible www.bleepingcomputer.com Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

Guides related to this story

← Back to all news