The Cybersecurity and Infrastructure Security Agency has added two critical, actively exploited zero day vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to patch affected systems by September 30. Both flaws carry a CVSS severity score of 9.5, near the top of the scale, and security researchers say attackers were exploiting them before patches became available.
According to reporting from Security Affairs, initial warnings came not from Citrix itself but from IT providers and security teams who began flagging suspicious activity on September 26. Researchers at watchTowr subsequently confirmed the reports were credible, and the Dutch National Cyber Security Centre issued a pre notification to organizations in the Netherlands before the vulnerabilities became broadly known.
What the two flaws do
The first, tracked as CVE-2026-88771, is a remote code execution vulnerability caused by improper input validation. It affects NetScaler ADC and Gateway deployments running in their default configuration, meaning organizations did not need to have enabled any unusual feature to be exposed.
The second, CVE-2026-88772, is a memory buffer overflow vulnerability that can also lead to remote code execution or denial of service. It specifically affects systems with DTLS, a protocol used to secure UDP based communications, enabled.
CISA said in its alert that it has received reports and partner threat intelligence confirming that threat actors are actively exploiting both vulnerabilities globally, though the agency has not publicly attributed the activity to a specific threat actor or group.
Who needs to patch, and by when
Citrix has released fixed builds for the affected product lines: NetScaler ADC and Gateway 14.1-73.37 and later, and 13.1-64.23 and later, along with corresponding updates for the FIPS and NDcPP variants used by government and regulated customers. CISA’s binding operational directive requires federal civilian executive branch agencies to apply those fixes by September 30, a compressed timeline that reflects the severity of the flaws and evidence of exploitation already underway.
Private sector organizations are not bound by the federal directive, but security researchers are urging the same urgency. NetScaler appliances sit at the network edge, handling application delivery, load balancing and remote access for thousands of enterprises, which makes a remote code execution flaw in default configuration a particularly attractive target: a successful exploit can give an attacker a foothold inside a corporate network without requiring any prior access or social engineering.
A familiar pattern for NetScaler
This is not the first time NetScaler appliances have drawn urgent attention from CISA and the broader security community. The product line has been targeted repeatedly in recent years by both ransomware operators and state linked groups looking for an initial foothold into enterprise networks, in part because of how widely NetScaler is deployed and how much access a compromised appliance can grant once breached.
The involvement of a national cybersecurity agency, the Dutch NCSC, in pre notifying organizations before public disclosure also underscores how seriously European governments are treating the exposure, even as the immediate compliance deadline applies only to United States federal agencies.
What security teams should do now
For chief information security officers, the guidance is straightforward: identify every NetScaler ADC and Gateway instance in the environment, confirm whether DTLS is enabled, and apply the patched builds without waiting for a broader change management cycle given confirmed active exploitation. Organizations that cannot patch immediately should consider taking exposed management interfaces offline or restricting access until remediation is complete, since the combination of a 9.5 severity score and confirmed in the wild exploitation leaves little room for a wait and see approach.
The episode is also a reminder that CISA’s Known Exploited Vulnerabilities catalog, while framed as a compliance tool for federal agencies, functions in practice as an early warning system for the wider enterprise security community. A KEV listing tends to trigger a scramble across vendor advisories, incident response teams and managed security providers well beyond the government customers the directive technically covers, and NetScaler’s install base across finance, healthcare and government makes this particular addition one worth tracking closely in the days ahead.

Leave a Reply