CISA adds two critical Citrix NetScaler flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway to its Known Exploited Vulnerabilities catalog after receiving reports and partner intelligence of active exploitation worldwide. Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS score of 9.5.
CISA said the flaws are being exploited globally and urged organizations to assess their exposure, prioritize remediation and incorporate the risk into their security-management activities. Federal Civilian Executive Branch agencies must apply the fixes by September 30, 2026.
Two flaws with different exposure conditions
CVE-2026-88771 is an improper input validation vulnerability that can allow an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments, making asset identification and patch status especially important.
CVE-2026-88772 is an improper restriction of operations within the bounds of a memory buffer. It can lead to remote code execution or denial of service, but requires DTLS to be enabled on a NetScaler ADC or Gateway appliance. DTLS is enabled by default on VPN virtual servers.
The affected VPN virtual-server configuration includes add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE. Organizations using NetScaler for remote access should therefore determine whether their VPN virtual servers use the relevant default DTLS setting as part of their exposure review.
Patched releases and incident response
Citrix addressed both issues in NetScaler ADC and Gateway 14.1-73.37 and later, and in 13.1-64.23 and later releases of the 13.1 branch. The fixes are also available in NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later, plus NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases.
The KEV catalog is intended to highlight vulnerabilities with evidence of exploitation; CISA's Known Exploited Vulnerabilities catalog illustrates how CISA uses the catalog to focus remediation on issues attackers are already using. CISA noted that NetScaler updates can be operationally complex and may require downtime, which makes advance maintenance planning important.
Citrix has published generic indicators of compromise through NetScaler Console to help customers assess whether a deployment may have been affected. If compromise is suspected, Citrix recommends preserving evidence from the NetScaler ADC VPX instance, isolating the device, revoking credentials and access, and investigating systems connected to the appliance for signs of follow-on compromise.
The vendor further advises rebuilding the device and installing current firmware, rotating local-account passwords and Key Encryption Keys, replacing restored SSL certificates when recovering from a known-good backup, and hardening the appliance using best practices. For businesses, the immediate implication is to inventory NetScaler ADC and Gateway systems, validate DTLS exposure on VPN services, coordinate an update window, and prepare containment and credential-rotation procedures before evidence of compromise appears.

