CISA orders feds to patch exploited Citrix NetScaler flaws by Wednesday
CISA added two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) to its KEV catalog and ordered federal agencies to patch them by September 30. Both allow unauthenticated remote code execution, and active exploitation has been confirmed.
- CVE-2026-88771 and CVE-2026-88772 allow unauthenticated RCE on NetScaler ADC and Gateway
- Citrix confirmed zero-day exploitation and released patches
- Shadowserver tracks over 23,000 internet-exposed NetScaler IPs
- FCEB agencies must remediate by September 30
Read next
Security