
Federal civilian agencies now have a binding deadline to secure their Citrix appliances against two actively exploited vulnerabilities. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog on Sunday and ordered Federal Civilian Executive Branch (FCEB) agencies to patch all vulnerable Citrix NetScaler instances by September 30, under Binding Operational Directive (BOD) 26-04.
What the two vulnerabilities allow
Both flaws enable unauthenticated remote code execution on vulnerable NetScaler appliances. The first affects all NetScaler ADC and NetScaler Gateway deployments running default configurations. The second requires DTLS to be enabled, and Citrix noted that DTLS is toggled on by default on VPN virtual servers. Citrix’s own advisory lists possible outcomes beyond remote code execution, including denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.
Citrix confirmed on Sunday that exploitation has been observed on unmitigated deployments and urged customers to install the relevant updated versions as soon as possible. The company published its warning in a blog post marked with a noindex meta tag that tells search engines not to index the page.
Which versions are patched and which are not
Fixed NetScaler ADC and NetScaler Gateway releases include 14.1-73.37 and later releases of 14.1, 13.1-64.23 and later releases of 13.1, 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP. NetScaler versions 12.1 and 13.0 have reached end of life and no longer receive security updates, and Citrix advised customers running those branches to migrate to a supported release.
What agencies and security teams should do before patching
CISA encouraged administrators to check for indications of compromise before applying updates, because patching can destroy forensic evidence. Citrix shared what it described as generic Indicators of Compromise through NetScaler Console, but warned that these IoCs might be of limited forensic value and might fail to identify actual compromises, and recommended retaining experienced forensic investigators where compromise is suspected. CERT-EU, the cybersecurity service for European Union institutions, bodies, offices, and agencies including the European Commission, the European Parliament, and the European Council, also strongly advised EU organizations to run a compromise assessment on any internet-facing appliance running an affected build.
How exposed are NetScaler appliances right now?
Threat watchdog Shadowserver is tracking more than 23,000 IP addresses with NetScaler fingerprints exposed on the public internet, including nearly 22,000 NetScaler ADC appliances and just over 1,500 NetScaler Gateway instances. Shadowserver has not broken down how many of those are honeypots, already remediated, or running vulnerable configurations. That total gives a sense of the potential blast radius if attackers find unpatched systems.
A pattern of in-the-wild Citrix exploitation in 2026
These two flaws are the latest in a string of Citrix vulnerabilities that attackers have exploited this year. In March, Citrix urged administrators to patch two other NetScaler flaws, CVE-2026-3055 and CVE-2026-4368, days before threat actors began abusing them. In early September, attackers began exploiting a NetScaler authentication bypass, CVE-2026-19490, that Citrix had patched in mid-August. Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, including six that ransomware gangs have abused. That history is part of why the September 30 deadline arrived so quickly after confirmation of active exploitation.
FAQ
What did CISA order federal agencies to do about Citrix NetScaler?
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by September 30, as required by Binding Operational Directive (BOD) 26-04.
Which NetScaler versions contain the patch?
Fixed releases include NetScaler ADC and NetScaler Gateway 14.1-73.37 and later, 13.1-64.23 and later of 13.1, 14.1-FIPS 14.1-73.37 FIPS and later of 14.1-FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later of 13.1-FIPS and 13.1-NDcPP. Versions 12.1 and 13.0 are end of life and must be migrated to a supported release.
Should organizations check for compromise before patching?
Yes. CISA encouraged administrators to look for indications of compromise before applying updates, because updates may remove forensic evidence. Citrix shared Indicators of Compromise through NetScaler Console, but warned they might be of limited forensic value and recommended engaging experienced forensic investigators where compromise is suspected. CERT-EU also advised EU organizations to run a compromise assessment on any internet-facing appliance running an affected build.
This article summarizes reporting from bleepingcomputer.com.
