The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added two critical vulnerabilities found in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are currently being exploited, prompting immediate attention from organizations worldwide.
Details of the Citrix NetScaler Vulnerabilities
Identified as CVE-2026-88771 and CVE-2026-88772, both vulnerabilities carry a CVSS score of 9.5, indicating severe risk. The first vulnerability, CVE-2026-88771, is due to improper input validation, allowing unauthorized attackers to execute arbitrary commands. The second, CVE-2026-88772, involves improper restrictions within memory buffers, potentially leading to remote code execution or denial-of-service attacks.
While CVE-2026-88771 affects all NetScaler ADC and Gateway deployments, CVE-2026-88772 specifically targets systems with DTLS enabled, a default setting on VPN virtual servers. Organizations must ensure their configurations are secure.
Solutions and Mitigation Measures
Citrix has addressed these vulnerabilities in several updated versions, including NetScaler ADC and Gateway 14.1-73.37 and later, and 13.1-64.23 and later for version 13.1. CISA urges organizations to update their systems promptly to these versions or newer to mitigate risks.
For detection, Citrix has provided generic indicators of compromise (IoCs) accessible via the NetScaler Console. In cases of suspected breaches, organizations are advised to preserve evidence, isolate affected devices, revoke access credentials, and conduct thorough investigations.
Urgent Action Recommended by CISA
Given the active exploitation of these vulnerabilities, CISA emphasizes the importance of integrating these risks into organizational risk management strategies. Although updating Citrix NetScaler appliances can be complex, involving potential downtime, it is crucial to prioritize these fixes to safeguard network security.
Federal Civilian Executive Branch (FCEB) agencies are mandated to implement these fixes by September 30, 2026. Organizations are encouraged to follow best practices for device hardening and to regularly rotate passwords and encryption keys to bolster security.
In conclusion, the active exploitation of these Citrix NetScaler vulnerabilities necessitates urgent attention and action from all impacted organizations. By swiftly applying the necessary updates and following recommended security measures, organizations can significantly reduce the risk of exploitation.
