Close Menu
NCIJ Network NCIJ Network
    What's Hot

    UK-Iranian dual national arrested over RAF Fairford investigation bailed

    October 3, 2026

    20% Off Brooks Promo Code | October 2026

    October 3, 2026

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • UK-Iranian dual national arrested over RAF Fairford investigation bailed
    • 20% Off Brooks Promo Code | October 2026
    • Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
    • Bankers sue to overturn OCC trust-bank rule used by crypto firms
    • Your gut may be making a molecule that raises Alzheimer’s risk
    • Tennessee prison chief to resign after Christa Pike’s failed execution
    • iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
    • Sazmining Launches The Wild Sats Club, A Loyalty Program That Discounts Mining Management Fees As Customer Hashrate Grows
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 28, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 28, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

    The vulnerabilities are listed below –

    • CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
    • CVE-2026-88772 (CVSS score: 9.5) – An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service.

    While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows –

    Cybersecurity

    add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE 

    Both the issues have been addressed in the versions below –

    • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
    • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
    • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
    • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

    “CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said.

    “Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.”

    Cybersecurity

    Citrix has also made generic indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended to perform the following steps to secure their environments –

    • Preserve evidence of the NetScaler ADC VPX instance.
    • Isolate the device.
    • Revoke credentials and access.
    • Investigate all servers and systems that the NetScaler ADC had connected to for any signs of further compromise.
    • Rebuild and update the firmware to the latest version.
    • Rotate all local account passwords, Key Encryption Keys (KEK), and replace all restored SSL certificates if restoring from a known good NetScaler backup.
    • Harden the device in line with best practices.

    In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes.

    Attackers CISA Citrix critical exploiting flaws globally NetScaler
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

    Fortra Patches Critical Vulnerabilities in BoKS

    Danish university DTU breach exposes data of up to 200,000 people

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    Kiteworks patches max severity code injection vulnerability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    UK-Iranian dual national arrested over RAF Fairford investigation bailed

    October 3, 2026

    20% Off Brooks Promo Code | October 2026

    October 3, 2026

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    October 3, 2026

    Bankers sue to overturn OCC trust-bank rule used by crypto firms

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    UK-Iranian dual national arrested over RAF Fairford investigation bailed

    October 3, 2026

    20% Off Brooks Promo Code | October 2026

    October 3, 2026

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.