Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Zero‑Day RCE Flaws (CVE‑2026‑88771/88772) in Citrix NetScaler Added to CISA’s KEV Catalog

CISA added two critical zero‑day vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog. Both CVEs score 9.5 and allow unauthenticated remote code execution, with one requiring DTLS enabled. The findings underscore the need for continuous control monitoring and rapid patch validation to maintain audit‑ready posture.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Zero‑Day RCE Flaws (CVE‑2026‑88771/88772) in Citrix NetScaler Added to CISA’s KEV Catalog

What It Is – CISA placed two Citrix NetScaler vulnerabilities (CVE‑2026‑88771 and CVE‑2026‑88772) into its Known Exploited Vulnerabilities (KEV) catalog. Both score 9.5 on the CVSS v3.1 scale and enable unauthenticated remote‑code execution.

Exploitability – Active exploitation was confirmed by multiple sources before patches were released; public proof‑of‑concepts are circulating.

Affected Products – Citrix NetScaler ADC and NetScaler Gateway appliances in their default configurations; the second CVE also requires DTLS, which is enabled by default on VPN vServers.

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of third‑party appliance configurations is a core control objective; a gap here can invalidate evidence across SOC 2, ISO 27001, NIST CSF and others.
  • Rapid patch validation and documented remediation provide defensible audit trails that enterprise buyers now demand.
  • Demonstrable oversight of network‑edge devices signals a mature vulnerability‑management program, strengthening overall trust posture.

Recommended Actions

  • Inventory all NetScaler ADC/Gateway instances and verify version numbers against the CVE list.
  • Apply Citrix’s emergency patches immediately; if patching cannot be completed, isolate the appliances from production traffic.
  • Capture remediation timestamps, configuration snapshots, and patch‑approval records as evidence for your control‑mapping framework.
  • Update your vulnerability‑management dashboard to flag any future NetScaler releases that affect the same control objective.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/199891/hacking/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →