[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4-eXhkGij0EjGz3Yx8GSZCZf5ZsQGa8MopgW2dkXEUY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"fb1a2c46-5b26-49af-8b6e-1c7deaf3ca83","actively-exploited-citrix-netscaler-vulnerabilities-added-to-cisa-kev-catalog","6451ff56-72e3-4e4b-a185-4ee147487a6f","Actively Exploited Citrix NetScaler Vulnerabilities Added to CISA KEV Catalog","Two critical vulnerabilities in Citrix NetScaler (CVE-2026-88771 and CVE-2026-88772) have been added to CISA's Known Exploited Vulnerabilities Catalog after evidence of active exploitation in the wild was confirmed. NetScaler devices are widely deployed as internet-facing network appliances, making unpatched instances a high-value target for threat actors seeking initial access to enterprise environments. The addition to the KEV Catalog triggers mandatory remediation timelines for Federal Civilian Executive Branch agencies under BOD 26-04, highlighting the government's recognition that delayed patching of publicly exposed assets poses unacceptable risk. This incident underscores that known, catalogued vulnerabilities — not zero-days — remain among the most commonly exploited vectors, often because organizations lack disciplined patch cadences for network infrastructure.","**Immediate Actions:**\n- Apply Citrix-released patches or mitigations for CVE-2026-88771 and CVE-2026-88772 on all NetScaler instances immediately.\n- Audit all internet-facing NetScaler deployments and isolate any systems that cannot be patched within the BOD 26-04 mandated timeframe.\n- Subscribe to CISA KEV Catalog alerts to receive real-time notification when new exploited vulnerabilities are published.\n\n**Long-Term Improvements:**\n- Establish a formal emergency patching SLA (e.g., ≤72 hours) specifically for vulnerabilities listed in the CISA KEV Catalog affecting internet-exposed assets.\n- Maintain a continuously updated and accurate inventory of all network appliances, including version and patch-level tracking.\n- Implement network segmentation to limit lateral movement potential if a perimeter device such as NetScaler is compromised.\n\n**Detection Measures:**\n- Deploy continuous vulnerability scanning targeted at internet-facing infrastructure to identify unpatched systems before attackers do.\n- Enable detailed logging on NetScaler devices and forward logs to a SIEM for anomaly detection and threat hunting.\n- Integrate threat intelligence feeds that correlate observed network traffic against known exploitation indicators for KEV-listed CVEs.",[12,13,14,15,16,17,18,19,20],"CIS Control 7 – Continuous Vulnerability Management","CIS Control 12 – Network Infrastructure Management","NIST SP 800-40 Rev. 4 – Guide to Enterprise Patch Management","NIST SP 800-53 SI-2 – Flaw Remediation","NIST SP 800-53 RA-5 – Vulnerability Monitoring and Scanning","CISA Binding Operational Directive (BOD) 22-01 – KEV Catalog Remediation","CISA Binding Operational Directive (BOD) 26-04","ITIL – Change and Release Management (Emergency Change Process)","NIST CSF 2.0 – ID.RA (Risk Assessment), RS.MI (Mitigation)","published","2026-09-27T22:20:40.214302+00:00","2026-09-27T22:20:40.069+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F09\u002F27\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-4aac97","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]