⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

September 28, 2026

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below – CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS score: 9.5) – An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service. While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled…

CVEs: CVE-2026-88771, CVE-2026-88772