CISA orders feds to patch exploited Citrix flaws by Wednesday

Citrix Flaw Exposes Feds to Zero-Day Attacks, CISA Orders Patching by Wednesday

In a stark reminder of the ongoing threat posed by unpatched vulnerabilities, the US government’s Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems against attacks exploiting two critical Citrix NetScaler flaws. The agency’s directive comes as Citrix itself confirmed active exploitation of these vulnerabilities in zero-day attacks.

The affected flaws, tracked as CVE-2026-88771 and CVE-2026-88772, are remote code execution bugs that allow unauthenticated attackers to gain control over vulnerable NetScaler appliances. These devices, used by organizations worldwide for various purposes including load balancing and application delivery controllers (ADCs), can be exploited even with default configurations.

Citrix’s own security updates released earlier this month addressed the flaws, which were first identified as potential vulnerabilities in June. However, it was not until national cybersecurity agencies, IT suppliers, and security teams began privately warning Citrix customers about the risks that the company acknowledged active exploitation of these bugs. The Dutch National Cyber Security Center (NCSC-NL) warned organizations in the Netherlands specifically about two critical NetScaler zero-days without CVE IDs, which allowed threat actors to place shellcode directly into memory.

As a result of this widespread exploitation, CISA has added both flaws to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch agencies to patch all vulnerable Citrix appliances by September 30. This is in line with Binding Operational Directive (BOD) 26-04, which mandates timely remediation of identified vulnerabilities.

Citrix has provided some guidance for identifying compromised systems through generic indicators of compromise shared via NetScaler Console. However, the company warns that these IoCs may have limited forensic value and could fail to identify actual compromises. As a result, Citrix advises customers to retain the services of experienced forensic investigators if they suspect their systems have been compromised.

The latest exploit is part of a long string of vulnerabilities in Citrix products, with over 26 actively exploited flaws flagged by CISA since November 2021. This includes six abused by ransomware gangs. Shadowserver, a threat watchdog organization, has identified nearly 23,000 IP addresses associated with NetScaler fingerprints exposed on the Internet.

Given the severity of this situation and the potential consequences of successful exploitation, it is crucial for organizations to take immediate action to secure their systems against these vulnerabilities. Users and administrators are encouraged to review Citrix’s advisories, check for indications of compromise prior to patching if possible, and preserve forensic evidence before applying updates. This will ensure that any necessary remediation does not inadvertently destroy valuable evidence in the event of an actual breach.

As a practical takeaway, organizations should prioritize patching their systems against these vulnerabilities as soon as possible. Regular vulnerability scanning and monitoring can also help identify potential weaknesses and enable timely remediation. Furthermore, maintaining up-to-date system configurations, including default settings for Citrix products like NetScaler appliances, is essential in preventing exploitation of known bugs.


Source: Bleeping Computer — 2026-09-28