[Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway]: Citrix NetScaler Zero-Days Added to CISA KEV

A close-up of a hand inserting a USB drive into a laptop port, highlighting technology and connectivity.

What should Citrix NetScaler ADC and Gateway administrators do before applying patches for the exploited zero-days?

A close-up of a hand inserting a USB drive into a laptop port, highlighting technology and connectivity.

CISA’s practical advice for Citrix NetScaler ADC and NetScaler Gateway administrators was not just “patch.” The agency urged users and administrators to review Citrix’s advisories and, where possible, look for signs of compromise before applying patches.

What admins should do first

Before patching, administrators should use Citrix’s advisories as the main technical reference and check for possible signs of compromise where they can.

That matters because CISA reported active global exploitation of the vulnerabilities based on reports and partner threat intelligence. The supplied context does not list indicators, logs to inspect, or product-specific patch steps, so those details should come from Citrix’s advisories and official CISA updates.

Which vulnerabilities are involved

CISA identified CVE-2026-88771 and CVE-2026-88772 as critical zero-day issues. CISA also added both to its Known Exploited Vulnerabilities Catalog.

The agency says each of those two vulnerabilities can separately allow remote code execution.

Keep the guidance current

Because this is an actively exploited security issue, check CISA and Citrix’s official materials before acting on technical steps, indicators, or patch sequencing.

Which Citrix NetScaler vulnerabilities were added to CISA’s Known Exploited Vulnerabilities Catalog?

From above of optical switch equipment with many similar connectors with rubber cables and metal parts

CISA added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2026-88771 and CVE-2026-88772.

The CVEs added to the catalog

The two catalog additions identified in the supplied context are:

  • CVE-2026-88771
  • CVE-2026-88772

CISA described both as critical zero-day issues affecting Citrix NetScaler ADC and NetScaler Gateway products.

Why they matter

CISA says each vulnerability can separately allow remote code execution. The agency also reported active exploitation globally, based on reports and partner threat intelligence.

The broader Citrix disclosure highlighted eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products, but the supplied context specifically names CVE-2026-88771 and CVE-2026-88772 as the critical zero-days added to the KEV Catalog.

What to check next

For remediation details, administrators should review Citrix’s advisories and the latest CISA alerts. The supplied context does not include patch commands, affected version ranges, or compromise indicators.

Sources / Learn more

Related reading

Comments

Leave a Reply

[privacy-do-not-sell-link]

Discover more from Trending Issues Daily

Subscribe now to keep reading and get access to the full archive.

Continue reading