CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
Summary
CISA has added two critical vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog, citing active global exploitation. One of these flaws, CVE-2026-88771, has a CVSS score of 9.5 and is described as an improper input validation vulnerability.
IFF Assessment
The article details active exploitation of critical vulnerabilities in widely used infrastructure, indicating a significant risk to organizations.
Severity
The CVSS score of 9.5 reflects a critical severity, indicating a high potential impact and exploitability. This score is directly provided in the article.
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating these identified Citrix NetScaler vulnerabilities immediately due to active exploitation. Organizations using NetScaler devices need to be vigilant about signs of compromise and ensure their systems are secured against unauthenticated attacks.