{"id":284,"date":"2026-09-30T01:36:39","date_gmt":"2026-09-30T01:36:39","guid":{"rendered":"https:\/\/managedt.com\/blog\/cisa-citrix-netscaler-zero-day-kev\/"},"modified":"2026-09-30T13:07:51","modified_gmt":"2026-09-30T13:07:51","slug":"cisa-citrix-netscaler-zero-day-kev","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/cisa-citrix-netscaler-zero-day-kev\/","title":{"rendered":"CISA Adds Two Citrix NetScaler Zero-Day Flaws to KEV Catalog"},"content":{"rendered":"<p>Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway can be independently exploited to run code on affected appliances, and attackers are already using them in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) added both flaws, tracked as CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) Catalog after receiving reports and partner threat intelligence confirming global exploitation. Six additional flaws disclosed in the same Citrix bulletin round out an eight-vulnerability cluster admins need to address.<\/p>\n<p>Because Citrix NetScaler deployments often sit in front of critical applications and may need planned downtime to patch, CISA is urging organizations to assess exposure quickly, check for evidence of compromise before applying updates, and fold the new flaws into ongoing vulnerability management work.<\/p>\n<h2>What CISA and Citrix disclosed<\/h2>\n<p>Citrix published a Security Bulletin covering CVE-2026-88771 through CVE-2026-88778, eight new flaws affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. CISA singled out the first two as zero-days that are both critical and under active exploitation:<\/p>\n<ul>\n<li>CVE-2026-88771, a critical zero-day enabling remote code execution.<\/li>\n<li>CVE-2026-88772, a separate critical zero-day that can also be exploited alone to achieve remote code execution.<\/li>\n<\/ul>\n<p>CISA added both CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog. The other six identifiers in the bulletin, CVE-2026-88773 through CVE-2026-88778, were disclosed in the same advisory and are part of the same cluster admins need to review.<\/p>\n<h2>Why these flaws matter<\/h2>\n<p>NetScaler ADC and NetScaler Gateway are commonly deployed as the public entry point for enterprise networks, including VPN and remote access paths, application delivery, and authentication. A remote code execution flaw on one of those appliances gives an attacker the ability to run commands on the perimeter device itself, which is often a high-value foothold for follow-on activity.<\/p>\n<p>The KEV Catalog exists to flag vulnerabilities that have evidence of active exploitation and that pose a clear risk to federal agencies and critical infrastructure. Listing a flaw in KEV also triggers remediation timelines for federal civilian agencies and signals private sector organizations to act.<\/p>\n<p>Independent exploitation is a key detail here. CISA&#8217;s wording indicates that each of the two KEV flaws can be used on its own, so defenders cannot treat one as the only urgent issue.<\/p>\n<h2>What to do now<\/h2>\n<p>CISA&#8217;s alert lays out a specific order of operations that protects forensic evidence while still moving quickly:<\/p>\n<ul>\n<li>Review the Citrix Security Bulletin for CVE-2026-88771 through CVE-2026-88778 and identify every NetScaler ADC or instance that looks in scope.<\/li>\n<li>Before patching, check for indicators of compromise. Citrix has published indicators of compromise through the NetScaler Console, and the bulletin includes additional guidance on spotting potential compromise.<\/li>\n<li>If compromise is suspected, preserve forensic evidence before applying updates. Updates may reduce or remove forensic visibility, so capturing logs, memory, and configuration snapshots first is important.<\/li>\n<li>Apply the Citrix-recommended updates as soon as it is safe to do so, and validate that appliances are rebuilt from a known-clean state where compromise is confirmed.<\/li>\n<li>Fold CVE-2026-88773 through CVE-2026-88778 into the same review, even though only the first two are in KEV, so the cluster is closed out together.<\/li>\n<\/ul>\n<p>Planning for a maintenance window is reasonable, but organizations should not delay the compromise-assessment step while waiting for that window. Knowing whether an attacker was already inside changes the urgency of the entire response.<\/p>\n<h2>How to assess exposure quickly<\/h2>\n<p>Two questions cut through the noise on these alerts: is the appliance in scope, and is there any sign it has already been touched. The first is a configuration question. Match the organization and version ranges in the Citrix bulletin against the inventory of NetScaler ADC and instances. The second is a detection question, and Citrix&#8217;s indicators of compromise and Console guidance are the place to start before pulling in third-party tooling.<\/p>\n<p>For teams that need a faster cross-check on which appliances may be internet-facing and unpatched, a technical audit of the perimeter can show what is actually exposed. SEOScanPro runs a comprehensive audit that surfaces externally visible configuration issues, which can be a useful sanity check alongside the Citrix-specific guidance.<\/p>\n<h2>Tracking the cluster after patching<\/h2>\n<p>Patching is not the end of the work. With two KEV flaws already being exploited, post-patch monitoring for signs of persistence on any appliance that was exposed in the unpatched window is the next step. That includes reviewing authentication logs, looking for unexpected admin accounts or configuration changes, and watching outbound traffic from NetScaler appliances for connections to known malicious infrastructure.<\/p>\n<h2>FAQ<\/h2>\n<h3>Which Citrix vulnerabilities did CISA add to the KEV Catalog?<\/h3>\n<p>CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities Catalog. Both are critical zero-day flaws in Citrix NetScaler ADC and Citrix NetScaler Gateway that can independently enable remote code execution, and CISA confirmed active exploitation globally.<\/p>\n<h3>Are there other Citrix NetScaler flaws in the same advisory?<\/h3>\n<p>Yes. The Citrix Security Bulletin covers eight vulnerabilities in total: CVE-2026-88771 through CVE-2026-88778. CISA highlighted the first two for KEV listing, and the other six should be reviewed and remediated as part of the same cluster.<\/p>\n<h3>What should organizations do before patching NetScaler ADC?<\/h3>\n<p>CISA recommends reviewing the Citrix bulletin, checking the NetScaler Console for indicators of compromise, and preserving forensic evidence (logs, memory, and configuration snapshots) before applying updates, since updates can remove forensic visibility. After that, apply the Citrix-recommended updates and validate that any compromised appliances are rebuilt from a known-clean state.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Which Citrix vulnerabilities did CISA add to the KEV Catalog?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CISA added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities Catalog. Both are critical zero-day flaws in Citrix NetScaler ADC and Citrix NetScaler Gateway that can independently enable remote code execution, and CISA confirmed active exploitation globally.\"}},{\"@type\":\"Question\",\"name\":\"Are there other Citrix NetScaler flaws in the same advisory?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. The Citrix Security Bulletin covers eight vulnerabilities in total: CVE-2026-88771 through CVE-2026-88778. CISA highlighted the first two for KEV listing, and the other six should be reviewed and remediated as part of the same cluster.\"}},{\"@type\":\"Question\",\"name\":\"What should organizations do before patching NetScaler ADC?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CISA recommends reviewing the Citrix bulletin, checking the NetScaler Console for indicators of compromise, and preserving forensic evidence (logs, memory, and configuration snapshots) before applying updates, since updates can remove forensic visibility. After that, apply the Citrix-recommended updates and validate that any compromised appliances are rebuilt from a known-clean state.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/27\/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway\" target=\"_blank\" rel=\"nofollow noopener\">cisa.gov<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA confirmed active exploitation of two critical Citrix NetScaler zero-day flaws and added them to the KEV Catalog, alongside six additional vulnerabilities.<\/p>\n","protected":false},"author":3,"featured_media":300,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-284","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/284","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=284"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/284\/revisions"}],"predecessor-version":[{"id":285,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/284\/revisions\/285"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/300"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}