CISA Adds Citrix NetScaler Flaws To Known Exploited Vulnerabilities Catalog

CISA Adds Citrix NetScaler Flaws To Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and NetScaler Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after receiving reports of active exploitation targeting affected systems globally. The agency said partner threat intelligence and collected reports confirmed that threat actors are actively exploiting the vulnerabilities, prompting organizations to assess their exposure and prioritize available security measures.

The vulnerabilities identified as CVE-2026-88771 and CVE-2026-88772 have both received a critical severity rating with a CVSS score of 9.5. CVE-2026-88771 is an improper input validation vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway deployments. The flaw could allow an unauthenticated attacker to execute arbitrary commands on affected systems, potentially enabling unauthorized actions within vulnerable environments. CVE-2026-88772 is an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow remote code execution or denial of service conditions. However, this issue specifically affects deployments where the DTLS configuration is enabled on NetScaler ADC or NetScaler Gateway systems. Citrix noted that the DTLS option is enabled by default on VPN virtual servers, making it important for organizations to review their configurations and determine whether their systems require immediate attention. The affected configuration includes VPN virtual servers operating with the relevant SSL settings. Citrix has released security updates addressing both vulnerabilities across multiple product versions, including NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases, 13.1-64.23 and later releases of the 13.1 branch, along with updated versions for NetScaler ADC 14.1-FIPS and NetScaler ADC 13.1-FIPS and 13.1-NDcPP environments.

CISA stated that updating Citrix NetScaler appliances can be complex and may require service interruptions, which is why it issued the alert to help organizations evaluate potential exposure, prioritize mitigation activities, and include the vulnerabilities in their risk management processes. Due to the confirmed exploitation activity, Federal Civilian Executive Branch (FCEB) agencies have been given until September 30, 2026, to apply the required fixes and secure vulnerable deployments. Citrix has also made indicators of compromise (IoCs) available through NetScaler Console to help customers identify whether their systems may have been impacted. Organizations that suspect their NetScaler ADC environments have been compromised have been advised to preserve evidence from affected VPX instances, isolate impacted devices, revoke credentials and access permissions, and investigate connected servers and systems for additional signs of unauthorized activity.

Further recommended recovery steps include rebuilding affected devices, upgrading firmware to the latest available version, rotating local account passwords and Key Encryption Keys (KEK), and replacing restored SSL certificates when recovering from known good NetScaler backups. Organizations have also been encouraged to strengthen their NetScaler deployments by following recommended security hardening practices. The inclusion of these Citrix NetScaler vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog highlights the importance of timely patching and security monitoring for organizations using these platforms. Since NetScaler ADC and Gateway solutions are widely used for application delivery and remote access services, organizations that delay updates could face increased security risks, including unauthorized access attempts, service disruption, or further compromise of connected systems.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment