Technology

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News September 28, 2026 1 views
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Advertisement

CISA Warns of Global Exploitation of Two Critical Citrix NetScaler Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of two critical Citrix NetScaler flaws across the globe.

Known Exploited Vulnerabilities (KEV) Catalog Updated

On Sunday, CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of exploits targeting these vulnerabilities.

Details of Critical Vulnerabilities

  • CVE-2026-88771: This vulnerability (CVSS score: 9.5) is a proper input validation flaw that could allow an unauthenticated attacker to:

Exploit the flaw to execute arbitrary code on the affected system, leading to potential unauthorized access and compromise.

  • CVE-2026-88772: This vulnerability does not provide specific information about the exploit, but it is described as a critical flaw in the Citrix NetScaler ADC and Gateway products.

CISA advises users and administrators of Citrix NetScaler ADC and Gateway products to apply the necessary patches and updates to mitigate the risks associated with these vulnerabilities.

CISA Urges Immediate Actions

The agency strongly recommends that users and administrators of Citrix NetScaler ADC and Gateway products take immediate action to protect their systems:

  • Update software: Apply the latest patches and updates provided by Citrix to address the identified vulnerabilities.
  • Monitor systems: Regularly monitor systems for any suspicious activity or unauthorized access attempts.
  • Enable security features: Enable security features such as Access Policy Manager (APM) and Web Interface Security to enhance system security.

CISA reminds users and administrators that failure to promptly address these flaws could lead to unauthorized access and potential data breaches.

Citrix Acknowledges and Provides Guidance

Citrix, the software company behind the affected products, has acknowledged the vulnerabilities and provided guidance for mitigating the risks:

  • Update software: Citrix recommends applying the latest patches and updates provided by the company to address the identified vulnerabilities.
  • Enable security features: Citrix advises users to enable security features such as Access Policy Manager (APM) and Web Interface Security to enhance system security.

The company urges users to take immediate action to protect their systems and prevent potential security threats.

<small>Source: The Hacker News — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement