[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG0obxYpsU2sVEa6E-GHelp9_Iu75TpGL6tjNbgM_7q0":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"4b39d3cf-fa76-4b03-9050-9c61a3305a0b","CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally","cisa-says-attackers-are-exploiting-two-critical-citrix-netscaler-flaws-globally-d10d67","The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to","CISA has added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway products to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, CVE-2026-88771 and CVE-2026-88772, are being actively exploited by threat actors worldwide, with both carrying a CVSS score of 9.5. While one allows for command execution and the other for remote code execution or DoS, CISA urges organizations to prioritize mitigation and risk management activities.","CISA adds two critical Citrix NetScaler flaws to KEV catalog due to active global exploitation.","CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally Ravie LakshmananSep 28, 2026Vulnerability \u002F Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service. While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows - add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE Both the issues have been addressed in the versions below - Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1 Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP \"CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,\" the agency said. \"Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.\" Citrix has also made generic indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended to perform the following steps to secure their environments - Preserve evidence of the NetScaler ADC VPX instance. Isolate the device. Revoke credentials and access. Investigate all servers and systems that the NetScaler ADC had connected to for any signs of further compromise. Rebuild and update the firmware to the latest version. Rotate all local account passwords, Key Encryption Keys (KEK), and replace all restored SSL certificates if restoring from a known good NetScaler backup. Harden the device in line with best practices. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes. Update watchTowr Labs, on September 28, 2026, said CVE-2026-88771 is rooted in a Perl script named \"ns_monuploadd_err.pl\" that's used to process NetScaler crash\u002Ferror information. The preemptive exposure management firm found that the script constructs a shell command using input that can be influenced by an attacker to achieve remote code execution as root. In other words, an unauthenticated attacker can inject arbitrary shell commands through data that NetScaler writes to its logs, which is then fed as input to a shell command, leading to command injection and remote code execution. This, in turn, can be achieved by sending a pre-authentication request to the \"\u002Fnf\u002Fauth\u002FdoAuthentication.do\" endpoint to trigger the flaw - POST \u002Fnf\u002Fauth\u002FdoAuthentication.do HTTP\u002F1.1 Host: netscaler-aaa-server Content-Type: application\u002Fx-www-form-urlencoded login=\u003C@urlencode_all>pitboss PPE unexpectedly died NSPPE;:`id>\u002Fvar\u002Ftmp\u002FwatchTowr`;# X\u003C\u002F@urlencode_all>&passwd=x&savecredentials=false&nsg-x1-logon-button=Log+On Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Citrix, Cyber Attack, network security, Vulnerability ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcisa-says-attackers-are-exploiting-two.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjG1pBfETB-EOlAvKfZwROp5B3Nr3d00xBbxRPhsq5hDBvK8QTVYmc2r8tR8RNz7omvXWoufetWbVk1S-tZ74b-z0nxsHS_Zz7XnN4Vs7VGvDtlnOhsfG0ecx-LX_kuRwBLJwkIMN-26auGXjzdcAS2Yz8sdQ2U_kDtKpQOnOYD18r6WEu1twQ79p_ZJGhD\u002Fs1600\u002Fct.jpg","2026-09-28T07:21:49+00:00","2026-09-28T18:00:47.47935+00:00",9,[18,21,23,26,28,31],{"name":19,"type":20},"Citrix NetScaler ADC","product",{"name":22,"type":20},"Citrix NetScaler Gateway",{"name":24,"type":25},"Citrix","vendor",{"name":27,"type":20},"NetScaler Console",{"name":29,"type":30},"DTLS","technology",{"name":32,"type":20},"NetScaler VPX","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56],{"type":53,"value":54,"context":55},"cve","CVE-2026-88771","Improper input validation vulnerability allowing arbitrary command execution.",{"type":53,"value":57,"context":58},"CVE-2026-88772","Improper restriction of operations within memory buffer vulnerability allowing RCE or DoS."]