CISA sets Wednesday deadline for agencies to patch Citrix NetScaler flaws
CISA has directed federal agencies to fix two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that Citrix confirmed are being actively exploited in zero-day attacks. Both bugs let unauthenticated attackers achieve remote code execution, with the first hitting default configurations and the second requiring DTLS, which is on by default for VPN virtual servers. Citrix has issued patches and shared indicators of compromise, after agencies like the Dutch NCSC had already been privately warning organizations to shut down affected appliances.