CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

🇧🇷 PT 🇺🇸 EN

2026-09-28 00:00

← Back

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sundayaddedtwo critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows - Both the issues have beenaddressedin the versions below - "CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agencysaid. "Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities." Citrix has alsomadegeneric indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended toperform the following stepsto secure their environments - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes. watchTowr Labs, on September 28, 2026, saidCVE-2026-88771isrootedin a Perl...

Details

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sundayaddedtwo critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows - Both the issues have beenaddressedin the versions below - "CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agencysaid. "Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities." Citrix has alsomadegeneric indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended toperform the following stepsto secure their environments - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes. watchTowr Labs, on September 28, 2026, saidCVE-2026-88771isrootedin a Perl script named "ns_monuploadd_err.pl" that's used to process NetScaler crash/error information. The preemptive exposure management firm found that the script constructs a shell command using input that can be influenced by an attacker to achieve remote code execution as root.

In other words, an unauthenticated attacker can inject arbitrary shell commands through data that NetScaler writes to its logs, which is then fed as input to a shell command, leading to command injection and remote code execution. This, in turn, can be achieved by sending a pre-authentication request to the "/nf/auth/doAuthentication.do" endpoint to trigger the flaw - AI agents are already operating inside enterprises with growing access to sensitive systems and data—while security teams still lack the visibility, controls, and governance to keep that access in check. Attackers are using AI to accelerate reconnaissance, compromise identities and escalate access. See how security teams can fight back with runtime identity controls. Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free.