CISA gives agencies three days to patch two exploited Citrix NetScaler flaws
CISA added two Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Sunday after Citrix reported observed attacks on unmitigated systems.
CVE-2026-88771 allows unauthenticated arbitrary commands across default customer-managed ADC and Gateway deployments. CVE-2026-88772 can cause remote code execution or denial of service when DTLS is enabled, which Citrix says is the default on VPN virtual servers.
The clock is short.
CISA set September 30 as the federal due date and requires forensic triage. Citrix says customers should move immediately to the fixed builds: 14.1-73.37 or later, 13.1-64.23 or later, or the listed FIPS and NDcPP versions.
Citrix-managed cloud services are being upgraded by the company.
The document: CISA Known Exploited Vulnerabilities Catalog.
