Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Conservatives pledge to scrap £100,000 childcare ‘cliff edge’
    • Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives
    • Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
    • The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
    • OpenPayd eyes more acquisitions as it targets year-end Nasdaq listing and U.S. launch
    • Scientists just made a superconductor stronger using “empty space”
    • UK-Iranian dual national arrested over RAF Fairford investigation bailed
    • 20% Off Brooks Promo Code | October 2026
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA orders feds to patch exploited Citrix flaws by Wednesday

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 28, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.

    Citrix released security updates to address the flaws (tracked as CVE-2026-88771 and CVE-2026-88772) days after national cybersecurity agencies, IT suppliers, and security teams began privately contacting Citrix customers and advising them to shut down their NetScaler appliances.

    For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.

    On Sunday, Citrix confirmed active exploitation of the two vulnerabilities in zero-day attacks and urged customers to patch their systems immediately.

    Both flaws allow unauthenticated attackers to gain remote code execution on vulnerable NetScaler appliances. The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers).

    “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible,” the company warned in a Sunday blog post that has a ‘noindex’ meta tag which tells search engines not to index the page.

    “These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.”

    Citrix has also shared what it describes as “generic Indicators of Compromise” through NetScaler Console to help security teams identify NetScaler deployments that may have already been compromised. However, it also warned that these IoCs “might be of limited forensic value and might fail to identify actual compromises” and advised customers “to retain the services of experienced forensic investigators.”

    Currently, threat watchdog Shadowserver tracks over 23,000 IP addresses with NetScaler fingerprints exposed on the Internet (including nearly 22,000 NetScaler ADC appliances and just over 1,500 Gateway instances). However, there is no information on how many are honeypots, have already been patched, or have vulnerable configurations.

    Map of Internet-exposed NetScaler instances
    Map of Internet-exposed NetScaler instances (Shadowserver)

    ​​​On Sunday, CISA also added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30, as mandated by Binding Operational Directive (BOD) 26-04.

    “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories,” the cybersecurity agency warned.

    “If possible, users are encouraged to check for indication of compromise prior to patching. Citrix has made indicators of compromise available through NetScaler Console and published additional guidance. Should your organization suspect compromise, it is important to preserve forensic evidence prior to applying updates, as updates may result in loss of forensic visibility.”

    CERT-EU, the cybersecurity service for all European Union institutions, bodies, offices, and agencies (including the European Commission, the European Parliament, and the European Council), also “strongly” advised EU organizations to “run a compromise assessment on any internet-facing appliance running an affected build.” 

    These two flaws are just the latest of several other Citrix vulnerabilities that attackers have exploited in the wild since the start of the year.

    In March, Citrix urged admins to patch two other NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them in attacks. More recently, in early September, attackers began exploiting a NetScaler authentication bypass (CVE-2026-19490) patched in mid-August.

    Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, including six abused by ransomware gangs.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    CISA Citrix Exploited Feds flaws orders patch Wednesday
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

    Fortra Patches Critical Vulnerabilities in BoKS

    Danish university DTU breach exposes data of up to 200,000 people

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Conservatives pledge to scrap £100,000 childcare ‘cliff edge’

    October 3, 2026

    Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives

    October 3, 2026

    Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.