Attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add them to its Known Exploited Vulnerabilities (KEV) catalog over the weekend.[1][2][7]
The first flaw, tracked as CVE-2026-88771, is described as an improper input validation vulnerability that allows an unauthenticated attacker to execute arbitrary commands on affected appliances, earning a CVSS score of 9.5 and a critical rating.[1][2][7]
The second issue, CVE-2026-88772, stems from an improper restriction of operations within the bounds of a memory buffer and can enable remote code execution or denial-of-service against NetScaler devices, also scored 9.5 under CVSS and classified as critical.[1][7]
Security trackers report that exploitation is already occurring globally against exposed NetScaler ADC and Gateway instances, with victims observed across multiple sectors where these appliances are commonly deployed as remote access front-ends.[1][2][7]
The newly flagged bugs arrive on the heels of earlier high-profile NetScaler issues such as the memory overflow vulnerability CVE-2026-8452 and the authentication-bypass flaw CVE-2026-19490, both of which were swiftly added to CISA’s KEV after being abused in large-scale attacks against gateway and AAA virtual server configurations.[3][5][8]
Under Binding Operational Directive 26-04, federal civilian agencies are required to remediate KEV-listed vulnerabilities within tight deadlines once an entry is published, a requirement previously enforced for NetScaler bugs like CVE-2026-19490.[6][11][13]
Organizations running Citrix NetScaler ADC or Gateway should immediately inventory internet-facing instances, review Citrix’s latest security updates for these products, and apply new patches or mitigations as soon as operationally feasible, prioritizing systems configured as SSL VPN or other remote access gateways.[3][5][11] Where patching cannot be completed quickly, defenders should consider temporarily disabling non-essential remote access functionality, increasing monitoring for suspicious NetScaler traffic and authentication anomalies, and implementing compensating controls such as network segmentation to limit the blast radius of any compromise.
References
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- Weekly Threat Bulletin β September 16th, 2026 | F5 Labs
- AL26-019 – Vulnerabilities impacting Citrix NetScaler ADC and …
- Active Exploitation Alert: Citrix NetScaler ADC/Gateway …
- CISA KEV: NetScaler CVE-2026-88771 and CVE-2026-88772 Require …
- Previously patched Citrix NetScaler flaw exploited in the …
- Critical NetScaler Vulnerability Exploited in Attacks
- CVE-2026-8452: NetScaler DoS Flaw Now …
