Security/ citrix · netscaler · zero-day · cisa

Citrix NetScaler Hit by Eight Flaws, Two Actively Exploited

CISA says attackers are exploiting two of eight new NetScaler flaws, and patching without checking for compromise first could destroy the evidence.

Citrix's NetScaler ADC and Gateway appliances have eight new security holes, and attackers are already exploiting two of them.

CISA is amplifying Citrix's disclosure of eight vulnerabilities in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 through CVE-2026-88778. Two of them, CVE-2026-88771 and CVE-2026-88772, are critical zero-days that can each independently allow remote code execution, and CISA has added both to its Known Exploited Vulnerabilities catalog after confirming active, global exploitation. Citrix has published indicators of compromise through its NetScaler Console along with a security bulletin covering all eight CVEs. CISA wants administrators to check for signs of compromise before they patch, because the update process itself can erase the forensic evidence needed to tell if an attacker already got in.

NetScaler appliances sit at the network edge, handling remote access and load balancing for large organizations, which makes them a high-value target for ransomware crews and other intrusion actors. They're also notoriously disruptive to patch - CISA notes updates can require downtime - so the window between disclosure and full remediation is exactly when opportunistic attackers do the most damage.

That guidance to check before you patch is itself a tell: appliances built to sit exposed to the internet are exactly where attackers get the most mileage out of a head start before anyone notices.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →