CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, affecting Citrix NetScaler, have been identified as actively exploited and pose significant risks. The update aligns with Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of such high-risk vulnerabilities.

IFF Assessment

FOE

The addition of actively exploited vulnerabilities to CISA's KEV catalog indicates new threats that defenders must address, posing a risk to organizations.

Defender Context

Defenders should prioritize patching and mitigating vulnerabilities listed in CISA's KEV catalog, especially for publicly exposed assets. The inclusion of these Citrix NetScaler vulnerabilities highlights the need for continuous vulnerability management and rapid response to actively exploited flaws to prevent potential compromises.

Read Full Story →