CISA orders feds to patch exploited Citrix flaws by Wednesday

Citix Vulnerabilities Exposed in Massive Government Alert

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to US government agencies, ordering them to patch two critical Citrix NetScaler vulnerabilities by Wednesday. The move comes as national cybersecurity agencies, IT suppliers, and security teams have been privately advising customers to shut down their NetScaler appliances due to the high risk of exploitation.

The two flaws, tracked as CVE-2026-88771 and CVE-2026-88772, allow unauthenticated attackers to gain remote code execution on vulnerable NetScaler appliances. Citrix confirmed that active exploitation has already occurred in zero-day attacks, urging customers to patch their systems immediately. The company warned that the vulnerabilities vary by deployment configuration and enabled features, potentially allowing denial of service, HTTP request smuggling, policy bypass, and other malicious activities.

The affected agencies are part of the Federal Civilian Executive Branch (FCEB), which includes many US government departments and offices. CISA’s order is backed by Binding Operational Directive 26-04, which requires these agencies to secure all vulnerable Citrix appliances by September 30. The directive emphasizes the potential consequences of successful exploitation and encourages users and administrators to review Citrix’s advisories.

Citrix has shared generic Indicators of Compromise (IoCs) through NetScaler Console to help security teams identify potentially compromised systems. However, the company warned that these IoCs may not be reliable and advised customers to retain experienced forensic investigators to ensure accurate assessments.

The scale of the vulnerability exposure is significant, with over 23,000 IP addresses associated with NetScaler appliances exposed on the internet. Shadowserver tracks this number, but it’s unclear how many are honeypots or have already been patched. This raises concerns about the potential for widespread exploitation and the importance of prompt action.

Other cybersecurity agencies, including CERT-EU, have also sounded the alarm. They strongly advise EU organizations to run a compromise assessment on any internet-facing appliance running an affected build. These warnings come as part of a growing trend of Citrix vulnerabilities being exploited in the wild since the start of the year.

Citix has faced criticism for its handling of previous vulnerabilities, with several flaws exploited by attackers before patches were released. This latest alert serves as a stark reminder to organizations and individuals alike: patching and vigilance are essential components of maintaining security in today’s threat landscape.

The CISA directive is clear: agencies must secure their systems against these vulnerabilities within the next 48 hours. For other organizations, this should serve as a warning to review Citrix’s advisories and take immediate action to protect themselves from potential exploitation.


Source: Bleeping Computer — 2026-09-28