Back to advisories

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances are at immediate risk.

CRITICALAdvisorySep 28, 2026
Action required
Immediately inventory all Citrix NetScaler appliances, prioritize patching publicly exposed instances, and hunt for exploitation indicators including abnormal NetScaler process behavior and suspicious HTTP requests to management interfaces.
Affected products
NetScalerCitrix