Active Exploitation of Citrix NetScaler Vulnerabilities CVE-2026-88771 and CVE-2026-88772
CISA has added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog due to documented evidence of active in-the-wild exploitation.
CVE search metadata
CVE search record: CVE-2026-88771. KEV: no. Brief: Active Exploitation of Citrix NetScaler Vulnerabilities CVE-2026-88771 and CVE-2026-88772. Brief link: https://feed.craftedsignal.io/briefs/2026-09-citrix-kev/
CVE search record: CVE-2026-88772. KEV: no. Brief: Active Exploitation of Citrix NetScaler Vulnerabilities CVE-2026-88771 and CVE-2026-88772. Brief link: https://feed.craftedsignal.io/briefs/2026-09-citrix-kev/
What's new
- 1. poc_available Sep 27, 21:59 via sploitus
CISA has officially added two vulnerabilities affecting Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The identified vulnerabilities are CVE-2026-88771, which involves improper input validation, and CVE-2026-88772, which involves improper restriction of operations within the bounds of a memory buffer. These vulnerabilities are documented as frequent attack vectors that allow malicious actors to target organizations by exploiting weaknesses in input handling and memory management on network appliances. Given their inclusion in the KEV catalog, these flaws are considered high-risk, necessitating immediate remediation to prevent potential unauthorized access or system compromise. Defenders should prioritize patching all internet-facing NetScaler instances to mitigate the risk posed by these actively exploited CVEs.
Impact
Successful exploitation of these vulnerabilities in Citrix NetScaler appliances can grant attackers unauthorized control over affected assets. Because NetScaler devices often sit at the network edge as gateways or load balancers, compromise poses a significant risk to the integrity and confidentiality of the entire internal enterprise environment. Organizations that fail to patch these vulnerabilities risk total asset takeover by threat actors.
Recommendation
- Immediately identify all internet-facing Citrix NetScaler instances and apply the latest security patches provided by the vendor to address CVE-2026-88771 and CVE-2026-88772.
- Implement a risk-based vulnerability management program as recommended by CISA, prioritizing KEV catalog entries for immediate remediation.
- Audit network logs and administrative access logs for unusual activity originating from or targeting NetScaler management interfaces, as exploitation often involves unauthorized input or memory manipulation.
- Review CISA Binding Operational Directive 26-04 for guidance on required forensic checks for signs of compromise on assets where these vulnerabilities were present prior to patching.