CISA Orders Urgent Fixes for Exploited NetScaler Flaws

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler ADC and Gateway systems worldwide. The critical flaws can enable unauthenticated command execution, remote code execution, or denial of service, with CVE-2026-88772 affecting deployments where DTLS is enabled. Citrix has released fixes for supported 13.1 and 14.1 versions and provided indicators of compromise through NetScaler Console. Organizations should patch immediately, while suspected compromises require device isolation, credential rotation, investigation of connected systems, and a secure rebuild.

Reference: thehackernews.com