Skip to content
BreakingCoding

Citrix NetScaler flaws: CISA sets a Sept. 30 deadline

CISA added two Citrix NetScaler flaws, both scoring 9.5 of 10 on the CVSS severity scale, to its exploited-vulnerability list on September 27, giving federal agencies until September 30 to patch.

By Tech AI Wire Team

3 min read

XLinkedIn
A black rack-mount network appliance with the NetScaler wordmark on its front bezel, on a plain gray backdrop.

By the numbers

CVSS severity score for both flaws
9.5 / 10
actively exploited Citrix flaw CISA has flagged since 2021
26th
deadline for U.S. federal agencies to patch
Sept. 30

The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, says attackers are actively exploiting two flaws in Citrix NetScaler. NetScaler is a family of network appliances that sit in front of corporate apps and VPNs. CISA added both bugs to its Known Exploited Vulnerabilities catalog on September 27, 2026. That catalog is a public list of flaws confirmed to be under real-world attack. Federal civilian agencies now have until September 30 to fix them.

According to CISA's advisory, the two flaws are CVE-2026-88771 and CVE-2026-88772. Both score 9.5 out of a possible 10 on the Common Vulnerability Scoring System, or CVSS. That is a standard scale security teams use to rank how dangerous a bug is. A score above 9 means an attacker can usually take over a system with little effort and no special access.

What the two flaws do

CVE-2026-88771 is an input-validation bug. That means the software fails to properly check data it receives before acting on it. BleepingComputer reports that this flaw affects every NetScaler ADC and Gateway deployment running default settings. It lets an attacker run commands without logging in first.

CVE-2026-88772 is a memory-safety bug. The software can be tricked into reading or writing past the edge of a memory buffer it allocated. The Hacker News says this one only applies when a setting called DTLS is turned on. DTLS encrypts fast, connectionless traffic. It is switched on by default on any NetScaler configured as a VPN server. Exploiting it can crash the appliance or let an attacker run their own code.

CISA said "these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise." The agency did not name specific attackers. But BleepingComputer and The Hacker News both confirm exploitation is happening globally, not in a single incident.

Affected versions and what to check

ItemDetail
CVE-2026-88771Unauthenticated command execution, default configuration
CVE-2026-88772Memory-buffer bug, needs DTLS enabled (default on VPN setups)
Severity9.5 / 10 (CVSS) for both
Fixed inNetScaler ADC/Gateway 14.1-73.37 or later, 13.1-64.23 or later
Not fixedVersions 12.1 and 13.0 (past end of life; no patch coming)
Federal deadlineSeptember 30, 2026, under Binding Operational Directive 26-04

Binding Operational Directive 26-04 is CISA's order requiring U.S. federal civilian agencies to patch specific flaws by a set date. It only legally binds government agencies. But CISA publishes the same deadlines as guidance for every organization running the affected software.

BleepingComputer notes this is the 26th actively exploited Citrix flaw CISA has flagged since November 2021. That pace shows a pattern. Many companies expose NetScaler directly to the internet as a VPN endpoint, which makes it a recurring target.

What this means for developers

If your team runs NetScaler ADC or Gateway, check the build number now. Update to 14.1-73.37 or 13.1-64.23 or later. Anyone still on version 12.1 or 13.0 is out of support entirely and needs a migration plan, not just a patch.

Citrix has published indicators of compromise through the NetScaler Console. But the company itself warned they have "limited forensic value," according to BleepingComputer. Do not treat a clean scan as proof nothing happened. The Hacker News reports what to do if you suspect a prior breach. Isolate the device first. Revoke every credential and access token tied to it. Rebuild its firmware from a known-good image. Rotate all connected passwords before you reconnect it to the network.

Check your infrastructure code too. If a Terraform, Ansible, or similar config file pins a NetScaler image or version, update that reference as well. Otherwise a future redeploy could quietly bring back the old, vulnerable build.

Sources

  1. CISA Adds Two Known Exploited Vulnerabilities to Catalog - CISA
  2. CISA orders feds to patch exploited Citrix flaws by Wednesday - BleepingComputer
  3. CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally - The Hacker News

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.