Patch/Configuration Management

CISA warns organizations to patch 2 critical Citrix NetScaler RCEs

Citrix sign on its office building in Fort Lauderdale, Florida, USA, an American cloud computing and virtualization technology company.

The Cybersecurity and Infrastructure Security Agency (CISA) has advised federal agencies to patch two critical Citrix NetScaler remote code execution (RCE) zero-day flaws by this Wednesday.

Citrix released patches over the weekend for the two vulnerabilities – CVE-2026-88771 and CVE-2026-88772 – not long after government agencies worldwide and security researchers began advising Citrix customers that they should shut down their NetScaler appliances.

Both vulnerabilities have CVSS scores of 9.5 and are exposed in Citrix NetScaler ADC and Citrix NetScaler Gateway products.

“This incident may feel routine because we’ve seen the same pattern repeatedly: a critical vulnerability in an internet-facing edge device, active exploitation, and an urgent race to patch,” said Matt Hartman, chief strategy officer at the Merlin Group. “Despite the familiarity, defenders cannot afford complacency. NetScaler appliances sit at a highly-privileged entry point into enterprise networks, and recent incidents have shown how quickly threat actors move against edge infrastructure.”

Hartman said organizations should follow CISA’s guidance: patch immediately and actively hunt for signs that attackers may have already gained access.

Adam Marrè, chief information security officer at Arctic Wolf, explained that these NetScaler vulnerabilities are exactly the kind of vulnerabilities that keep security leaders up at night because they target the systems agencies depend on to connect users, deliver services, and secure access.

Marrè said mission-critical organizations don’t always have the option of taking these systems offline the moment a patch becomes available, but they also can’t afford to treat patching as the fix. The patch may close the vulnerability, said Marrè, but it doesn’t tell us whether an attacker already got in before it was applied.

“Organizations should treat patching as the beginning of the investigation process,” said Marrè. “The priority must be to identify affected NetScaler deployments, apply the fixes as quickly as possible, and validate whether any unauthorized activity occurred before remediation. One of the most important lessons from previous NetScaler incidents is that applying a patch does not remove the risk if an adversary already established a foothold. Security teams should terminate potentially exposed sessions, review logs, and actively hunt for signs of compromise.”

Stephen Fewer, senior principal security researcher at Rapid7, said the most notable part of this developing NetScaler situation is that there are not one, but two different unauthenticated RCE vulnerabilities being exploited as zero-days – and they were exploited prior to Citrix’s disclosure over the weekend.

Because of the pervasive nature of the NetScaler product and its position on the network edge, Fewer said we’re looking at “a recipe for a significant blast radius.”

Additionally, Fewer said CVE-2026-88771 affects all NetScaler appliances in a default configuration, so there’s no specific feature or configuration setting required for the appliance to be vulnerable. Fewer noted this is highly significant for an edge appliance because this means attackers will then have a huge amount of viable targets to exploit. In addition, Fewer said CVE-2026-88771 operates as a command injection vulnerability as opposed to a memory corruption vulnerability, which significantly increases the likelihood of successful exploitation as command injections are historically a very reliable RCE vector.

On the other hand, Fewer said CVE-2026-88772 has also been confirmed as being exploited in the wild, but it’s described by Citrix as a memory corruption vulnerability and requires a specific appliance configuration, meaning it’s much more complex for attackers to leverage it for successful exploitation.

“As of today, there’s already a public proof-of-concept exploit script for CVE-2026-88771 available, so we can expect broad exploitation to begin in the coming days in addition to the targeted zero-day exploitation that has already occurred,” noted Fewer.

Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds