Citrix NetScaler Vulnerabilities Trigger Urgent CISA Alert

Citrix NetScaler Vulnerabilities Trigger Urgent CISA Alert

By Satoshi Voice
Publication Date: 2026-09-28 17:13:00

Two new zero-day flaws in Citrix NetScaler appliances are already being used to break into corporate networks, and the scramble to patch them has pulled in Dutch and American cybersecurity agencies within the same 48-hour window. The disclosure adds fresh urgency to what has become a familiar story: critical Citrix NetScaler vulnerabilities are once again under active attack before most organizations have had a real chance to respond.

Key takeaways

  • Citrix disclosed eight CVEs affecting NetScaler ADC and NetScaler Gateway, with the security bulletin published on a Sunday.
  • Two flaws, CVE-2026-88771 and CVE-2026-88772, carry critical 9.5 CVSS scores and allow remote code execution; both are confirmed exploited in the wild.
  • A third critical bug, CVE-2026-88773, rated 9.3, enables HTTP request smuggling that can bypass front-end security controls.
  • The US Cybersecurity and Infrastructure Security Agency added the two exploited flaws to its Known Exploited Vulnerabilities catalog and…