Citrix Zero-Days Actively Exploited — Patch Immediately
Two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild, enabling remote code execution on affected systems. These products sit at the network perimeter and are high-value targets because compromising them can grant attackers broad access to internal infrastructure. The fact that these are zero-days means no patch existed at the time of initial exploitation, making rapid response and compensating controls essential. Organizations that fail to act immediately risk full network compromise, data exfiltration, and ransomware deployment. CISA's addition to the Known Exploited Vulnerabilities catalog signals this is not theoretical — real-world attacks are underway.
Tactical Insight
Immediate actions
- Apply the latest Citrix-issued patches or mitigations for CVE-2026-88771 and CVE-2026-88772 without delay.
- Isolate or take offline any unpatched NetScaler ADC or Gateway instances that are internet-facing until remediation is complete.
- Scan all Citrix appliances for indicators of compromise (IOCs) published by CISA before assuming systems are clean.
Long-term improvements
- Maintain a continuously updated inventory of all network appliances, including firmware and software versions, to accelerate future patch prioritization.
- Establish a formal emergency patching procedure with defined SLAs (e.g., 24–48 hours) for CISA KEV-listed vulnerabilities.
- Implement network segmentation to limit lateral movement opportunities if perimeter appliances are ever compromised.
Detection measures
- Deploy centralized logging and SIEM alerting on all NetScaler ADC and Gateway devices to detect anomalous authentication or execution events.
- Subscribe to CISA KEV catalog alerts and vendor security advisories to receive real-time notification of newly disclosed exploited vulnerabilities.
- Conduct regular threat-hunting exercises targeting perimeter devices using current threat intelligence feeds.