CISA Flags Critical Citrix NetScaler Flaws Amid Global Exploitation, Urges Immediate Action

September 27, 2026
CISA Flags Critical Citrix NetScaler Flaws Amid Global Exploitation, Urges Immediate Action
  • CISA has added two actively exploited Citrix NetScaler flaws (CVE-2026-88771 and CVE-2026-88772) to the Known Exploited Vulnerabilities catalog after reports of widespread global exploitation, with one flaw allowing unauthenticated remote code execution in NetScaler ADC and Gateway in default configurations and the other a memory-buffer-overflow on a DTLS-enabled VPN server that can enable RCE or DoS.

  • Citrix has released fixes and agencies are urged to review advisories, assess for compromise, and mitigate; federal civilian agencies must address the issues by the end of September 2026.

  • Additional Citrix CVEs of concern include CVE-2025-39964, a race condition on AF_ALG sockets that can cause crashes or DoS, and CVE-2025-39682, a TLS receive path flaw with a 9.8 CVSS score that could leak memory or cause DoS for authenticated local users.

  • Analysts emphasize the high cost and complexity of investigation and remediation, highlighting the need for thorough containment, patching, validation, and continuous monitoring.

  • Attackers reportedly used anti-forensics to erase traces, making log reviews and SIEM analysis critical after patching and during containment.

  • Some researchers advise temporarily disconnecting affected NetScaler devices as a precaution, though Citrix has not officially recommended this step.

  • Administrators are instructed to monitor for updates, reduce attack surfaces where possible, await official patches and statements, and coordinate input with entities like BSI, watchTowr, Citrix, and Kevin Beaumont.

  • The incident appears global in scope for Citrix customers, with Dutch organizations among the first to publicly report issues.

  • Editorial notes stress careful sourcing and corroboration among watchdogs while acknowledging the potential for error in high-stakes disclosures.

  • Incident-response guidance recommends SIEM searches for indicators such as base64 payloads and webshell signatures, and cautions that IOCs may be unreliable due to evolving attacker techniques, advising engagement of experienced forensic investigators.

  • Exploitation reportedly occurred before any fix existed, with no disclosed victims or published IOCs at the time of reporting, and official guidance pending.

  • Industry and researchers, including notable security figures, regard the exploits as credible, though remediation specifics remain unclear.

Summary based on 20 sources


Get a daily email with more Tech stories

More Stories