CISA sets Wednesday deadline for agencies to patch Citrix NetScaler flaws
CISA has directed federal agencies to fix two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that Citrix confirmed are being actively exploited in zero-day attacks. Both bugs let unauthenticated attackers achieve remote code execution, with the first hitting default configurations and the second requiring DTLS, which is on by default for VPN virtual servers. Citrix has issued patches and shared indicators of compromise, after agencies like the Dutch NCSC had already been privately warning organizations to shut down affected appliances.
GoKawiil's interpretation of the reporting above, not reported fact.
The private warnings issued before Citrix's public disclosure suggest attackers may have had a head start exploiting these flaws before defenders could patch. CISA's binding directive and tight deadline indicate the agency views the risk to federal networks as severe, given NetScaler's widespread use as an internet-facing gateway. Organizations that delay patching could face compromise similar to past NetScaler exploitation waves that have hit government and enterprise networks.
- CISA ordered federal agencies to patch two critical NetScaler flaws by Wednesday.
- Citrix confirmed active zero-day exploitation of CVE-2026-88771 and CVE-2026-88772, both enabling remote code execution.
- National agencies like NCSC-NL had privately warned organizations before Citrix's public advisory and patch release.
Source: bleepingcomputer.com, 2026-09-28
Published there as: “CISA orders feds to patch exploited Citrix flaws by Wednesday”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.