IC Technology & Cyber — 2026-09-30
CISA Adds Critical Citrix NetScaler Zero-Day Vulnerabilities to KEV Catalog After Active Exploitation
BLUFActive exploitation of two unauthenticated RCE flaws in Citrix NetScaler demands immediate patching, though exploitation of the six remaining bulletin vulnerabilities is unlikely by end of October.
Citrix's security bulletin on September 27 disclosed eight NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771 through CVE-2026-88778) and stated that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated deployments 1. CVE-2026-88771 is an unauthenticated input-validation flaw affecting all deployments in default configuration, and CVE-2026-88772 is a memory overflow affecting deployments with DTLS enabled, which is the default on VPN vServers; both carry CVSS v4.0 scores of 9.5 1. CISA added both to its KEV Catalog the same day, citing reports and partner intelligence confirming global exploitation, and urged organizations to check for compromise and preserve forensic evidence before patching 23. Fixed builds are 14.1-73.37 and 13.1-64.23 or later, with separate FIPS and NDcPP releases 1. The Hacker News reported that both flaws allow remote code execution and that the bulletin followed a watchTowr publication the previous day 4.
AnalysisPublic reporting of exploitation of the six remaining NetScaler flaws (CVE-2026-88773 through CVE-2026-88778) is
unlikely by October 31. Attackers already hold two unauthenticated remote code execution paths and have little reason to invest in request smuggling, policy bypass, denial-of-service or ISN prediction bugs while unpatched appliances remain plentiful. Confidence is low: vendor and government reporting, which anchors everything here, says nothing beyond the two KEV entries, and open sources show no telemetry. Exploitation of the others may already be occurring undetected, since whoever found the two zero-days likely knew the full set. A public proof-of-concept, especially one enabling chaining with CVE-2026-88773, would raise the odds. If exploitation is reported, administrators and federal agencies would need to treat all eight CVEs as urgent and widen compromise hunting. Until then, patching can be sequenced by KEV status.
4 sources
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway - CISA
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation - The Hacker News
View in full brief →