CISA sets Wednesday deadline for federal agencies to fix actively exploited Citrix NetScaler bugs

CISA told U.S. federal agencies to patch or secure systems against two critical Citrix NetScaler vulnerabilities by Wednesday after active exploitation was confirmed. Citrix released fixes for CVE-2026-88771 and CVE-2026-88772, which can let unauthenticated attackers run code remotely on vulnerable appliances. Shadowserver reported more than 23,000 internet-exposed NetScaler IP addresses.
Before Citrix publicly confirmed exploitation, Dutch authorities and other security teams privately alerted customers, reportedly describing two critical NetScaler zero-days that let attackers inject shellcode into memory. Citrix later issued fixes for CVE-2026-88771 and CVE-2026-88772 and said both could permit unauthenticated remote code execution. The first affects default ADC and Gateway setups; the second needs DTLS enabled, which Citrix says is default on VPN virtual servers.
CISA added both flaws to its Known Exploited Vulnerabilities catalog and gave Federal Civilian Executive Branch agencies until September 30 under Binding Operational Directive 26-04. Shadowserver counts over 23,000 exposed NetScaler IPs, mostly ADC appliances, though it is unclear how many are patched, honeypots, or vulnerable. CERT-EU urged compromise checks on internet-facing affected builds.
Count: first paragraph: Before(1) Citrix2 publicly3 confirmed4 exploitation5, Dutch6 authorities7 and8 other9 security10 teams11 privately12 alerted13 customers14, reportedly15 describing16 two17 critical18 NetScaler19 zero-days20 that21 let22 attackers23 inject24 shellcode25 into26 memory27. Citrix28 later29 issued30 fixes31 for32 CVE-2026-8877133 and34 CVE-2026-8877235 and36 said37 both38 could39 permit40 unauthenticated41 remote42 code43 execution44. The45 first46 affects47 default48 ADC49 and50 Gateway51 setups52; the53 second54 needs55 DTLS56 enabled57, which58 Citrix59 says60 is61 default62 on63 VPN6
The deadline may reduce exposure across U.S. federal systems, but many private and non-U.S. organizations could remain at risk. Because NetScaler appliances often guard remote access and internal applications, successful exploitation may let intruders run code, disrupt services, or reach sensitive data. Government agencies, EU institutions, and businesses relying on internet-facing NetScaler devices could face operational downtime, breach costs, and eroded trust. Rapid patching and compromise checks may limit harm, though already-compromised systems might require forensic investigation before remediation. Count: The1 deadline2 may3 reduce4 exposure5 across6 U.S.7 federal8 systems9, but10 many11 private12 and13 non-U.S.14 organizations15 could16 remain17 at18 risk19. Because20 NetScaler21 appliances22 often23 guard24 remote25 access26 and27 internal28 applications29, successful30 exploitation31 may32 let33 intruders34 run35 code36, disrupt37 services38, or39 reach40 sensitive41 data42.