CISA: two Citrix NetScaler flaws are being exploited, and each can run remote code
On 27 September 2026, CISA amplifies eight Citrix NetScaler ADC and Gateway flaws. Two of them, CVE-2026-88771 and CVE-2026-88772, are in the known exploited catalog. CISA says each can enable remote code execution, and that actors are exploiting them. Update on 2 October: a SIGMA rule.

Original AI-generated illustration · SecuFocus
At a glance
Key points
Here, exploitation is stated by CISA, not inferred. We did not inspect an appliance.
What changes
CISA’s 27 September 2026 alert, revised on 2 October, relays Citrix’s disclosure of eight flaws: CVE-2026-88771 through CVE-2026-88778. Two are added to the Known Exploited Vulnerabilities catalog: CVE-2026-88771 and CVE-2026-88772. CISA calls them critical zero-days and says each can independently enable remote code execution.
CISA writes that it has received reports and partner threat intelligence confirming active exploitation, globally. On 2 October it adds a SIGMA rule to help spot suspicious activity in relevant logs.
What can leave
An exposed NetScaler, if compromised, sits on the traffic path. This alert does not list data already taken. CISA asks administrators to look for compromise before patching, because an update can remove forensic visibility. Citrix publishes indicators through NetScaler Console.
What we did not check
We have no Citrix appliance, and we did not replay the CVEs. “Exploited” comes from CISA and from what it says it received. It is not a SecuFocus test.
The choice
If you run NetScaler ADC or Gateway, read the Citrix bulletin and the CISA alert before the update window. Look for compromise while the logs are still readable. Then update. An exposed appliance does not wait for a comfortable cycle.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.