The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered civilian federal government agencies to secure Citrix NetScaler devices affected by two critical vulnerabilities before September 30, after Citrix confirmed that they were actively exploited in zero-day attacks.
The two vulnerabilities are designated CVE-2026-88771 and CVE-2026-88772, and allow unauthenticated attackers to execute commands remotely on vulnerable NetScaler devices. The first vulnerability affects NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled, a feature Citrix indicated is enabled by default on virtual VPN servers.
What did CISA request?
CISA added the two vulnerabilities to its Known Exploited Vulnerabilities catalog and required agencies covered by Binding Operational Directive BOD 26-04 to remediate vulnerable devices within the specified deadline. It also urged users and system administrators to review Citrix guidance and check for indicators of compromise before installing the updates whenever possible.
The agency warns that installing the update may result in the loss of some forensic visibility. Therefore, organizations that suspect they have been compromised should preserve evidence before updating and consult forensic investigation experts when necessary.
Remediated versions and the status of older releases
Citrix released updates covering NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later, and 13.1-64.23 and later. Supported releases also include NetScaler ADC 14.1-FIPS version 14.1-73.37 FIPS and later, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP version 13.1.37.279 and later.
Versions 12.1 and 13.0 have reached end of support and do not receive security updates; Citrix recommends migrating devices running them to a supported version.
Why does this news matter?
The risk is not limited to regulatory compliance for U.S. agencies. Internet-facing NetScaler devices typically operate as access points or VPN gateways, making exploitation for remote command execution potentially impactful to enterprise networks. Shadowserver is observing more than 23,000 IP addresses with exposed NetScaler fingerprints on the internet, including approximately 22,000 ADC devices and slightly more than 1,500 Gateway devices, although no data is available identifying how many devices have been patched or are actually affected.
Citrix provided general indicators of compromise through NetScaler Console, but acknowledged that they may have limited forensic value and may not reveal all cases of compromise. Therefore, installing the fix alone is insufficient in environments where suspicious indicators appear; CISA and CERT-EU recommend conducting a compromise exposure assessment, particularly on devices directly connected to the internet.
Exploitation context
The two vulnerabilities come amid a series of NetScaler vulnerabilities exploited during the year. Citrix warned in March about CVE-2026-3055 and CVE-2026-4368, and exploitation of the authentication-bypass vulnerability CVE-2026-19490 began in early September after it was fixed in mid-August. Since November 2021, CISA has listed 26 exploited Citrix vulnerabilities, six of which were associated with attacks carried out by ransomware groups.