Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities can lead to remote code execution, allowing attackers to potentially take control of affected NetScaler appliances. CISA is urging organizations to review Citrix's advisories and take necessary steps to protect their systems from exploitation.
CISA has added two critical vulnerabilities in Citrix NetScaler to its KEV catalog: CVE-2026-88771 and CVE-2026-88772. The vulnerabilities are classified as high-severity exploits that can lead to remote code execution and unauthorized access. CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation. CVE-2026-88772 is a memory buffer overflow vulnerability that can lead to remote code execution or denial-of-service. Administrators have been advised to take NetScaler systems offline without explanation, raising concerns about transparency. CISA urges users and administrators to review Citrix's advisories and take necessary steps to protect their systems. Citrix has released generic indicators of compromise to help customers check for potential system compromise.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two critical vulnerabilities in Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have been classified as high-severity exploits that can lead to remote code execution, allowing attackers to potentially take control of affected NetScaler appliances.
The first vulnerability, CVE-2026-88771, is a remote code execution vulnerability caused by improper input validation. This flaw can be exploited by an unauthenticated remote attacker to execute arbitrary commands, which can lead to unauthorized access to the system. The vulnerability affects all NetScaler ADC and NetScaler Gateway deployments in their default configuration and does not require any additional features to be enabled.
The second vulnerability, CVE-2026-88772, is a memory buffer overflow vulnerability that can also lead to remote code execution or cause a denial-of-service condition. This flaw affects NetScaler ADC and NetScaler Gateway deployments with DTLS enabled, which is enabled by default on VPN vServers. The vulnerability is classified as CWE-119.
It is worth noting that Citrix has confirmed that these two critical zero-day vulnerabilities were exploited before the company released patches. The first warnings did not come from Citrix, and administrators were privately advised to take NetScaler systems offline, sometimes without explaining why.
Security researchers at watchTowr confirmed that the reports were credible, and the company stated that it was investigating reports of multiple unpatched NetScaler remote code execution flaws being exploited in the wild. The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands, warning them about the potential vulnerabilities.
CISA has issued an alert to help organizations assess their exposure, prioritize mitigation, and include the vulnerabilities in their risk-management activities. The agency urges users and administrators to review Citrix's advisories and take necessary steps to protect their systems.
Citrix has released generic indicators of compromise (IoCs) through NetScaler Console, which can help customers check whether their systems may have been compromised. If a compromise is suspected, Citrix recommends taking the following steps: preserving evidence, isolating the device, revoking credentials and access, checking connected servers and systems for signs of further compromise, rebuilding the device and updating it to the latest firmware, rotating local account passwords and Key Encryption Keys (KEK), and hardening the device according to Citrix security best practices.
The addition of these vulnerabilities to the KEV catalog highlights the growing concern for cybersecurity in the face of evolving threats. It is essential for organizations to stay vigilant and take proactive measures to protect their systems from exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Citrix-NetScaler-Flaws-to-Its-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Cybersecurity-ehn.shtml
https://securityaffairs.com/199891/hacking/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
https://nvd.nist.gov/vuln/detail/CVE-2026-88771
https://www.cvedetails.com/cve/CVE-2026-88771/
https://nvd.nist.gov/vuln/detail/CVE-2026-88772
https://www.cvedetails.com/cve/CVE-2026-88772/
Published: Mon Sep 28 06:05:27 2026 by llama3.2 3B Q4_K_M