CISA Orders Federal Agencies to Patch Citrix Vulnerabilities by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. government agencies to address security gaps in Citrix NetScaler systems following confirmed exploitation of two critical vulnerabilities.
CISA’s Mandate
The directive, issued over the weekend, requires federal entities to implement protective measures by September 30. The vulnerabilities, designated as CVE-2026-88771 and CVE-2026-88772, were disclosed by Citrix after cybersecurity organizations and IT vendors alerted affected parties to potential threats.
Vulnerabilities and Exploitation
Citrix’s Confirmation
Citrix confirmed on Sunday that these vulnerabilities are being actively exploited in attacks, emphasizing the urgency for mitigation. Both flaws enable remote code execution without authentication, with the first impacting all NetScaler ADC and Gateway setups using default configurations.
Dutch NCSC-NL Warnings
The Dutch National Cyber Security Center (NCSC-NL) had previously issued warnings about two unpatched NetScaler zero-day flaws without formal CVE identifiers, which enabled adversaries to inject malicious code directly into memory.
Citrix’s Response and Recommendations
Impact and Risks
The second vulnerability requires DTLS encryption to be enabled, a feature that is typically activated by default on VPN virtual servers. Citrix’s advisory highlighted that exploitation of the flaws has been observed in unpatched environments, urging immediate deployment of updated software versions.
Indicators of Compromise
Citrix provided generic indicators of compromise (IoCs) via the NetScaler Console, though it cautioned that these may have limited forensic utility and recommended engaging specialized investigators for thorough analysis.
Shadowserver’s Findings
Shadowserver, a threat intelligence organization, reported over 23,000 internet-exposed NetScaler instances, including 22,000 ADC appliances and 1,500 Gateway devices. However, the data does not clarify how many of these are honeypots, already patched, or still vulnerable.
CISA’s Enforcement
CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, enforcing compliance through Binding Operational Directive 26-04. The agency advised administrators to review Citrix’s guidance, check for signs of compromise before applying patches, and preserve forensic evidence to avoid data loss during updates.
Historical Context
This incident follows a series of Citrix vulnerabilities exploited in 2026. In March, two flaws (CVE-2026-3055 and CVE-2026-4368) were patched after attackers began leveraging them. A NetScaler authentication bypass (CVE-2026-19490) was also exploited in early September, despite a mid-August fix. Since November 2021, CISA has identified 26 actively exploited Citrix flaws, including six linked to ransomware operations.
Conclusion
The directive underscores the ongoing risks associated with unpatched systems and the need for proactive mitigation strategies. Organizations are urged to prioritize updates, monitor for suspicious activity, and collaborate with cybersecurity experts to address potential compromises.
