Critical Zero‑Day RCE Flaws (CVE‑2026‑88771/88772) in Citrix NetScaler Added to CISA’s KEV Catalog
What It Is – CISA placed two Citrix NetScaler vulnerabilities (CVE‑2026‑88771 and CVE‑2026‑88772) into its Known Exploited Vulnerabilities (KEV) catalog. Both score 9.5 on the CVSS v3.1 scale and enable unauthenticated remote‑code execution.
Exploitability – Active exploitation was confirmed by multiple sources before patches were released; public proof‑of‑concepts are circulating.
Affected Products – Citrix NetScaler ADC and NetScaler Gateway appliances in their default configurations; the second CVE also requires DTLS, which is enabled by default on VPN vServers.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of third‑party appliance configurations is a core control objective; a gap here can invalidate evidence across SOC 2, ISO 27001, NIST CSF and others.
- Rapid patch validation and documented remediation provide defensible audit trails that enterprise buyers now demand.
- Demonstrable oversight of network‑edge devices signals a mature vulnerability‑management program, strengthening overall trust posture.
Recommended Actions
- Inventory all NetScaler ADC/Gateway instances and verify version numbers against the CVE list.
- Apply Citrix’s emergency patches immediately; if patching cannot be completed, isolate the appliances from production traffic.
- Capture remediation timestamps, configuration snapshots, and patch‑approval records as evidence for your control‑mapping framework.
- Update your vulnerability‑management dashboard to flag any future NetScaler releases that affect the same control objective.
Source: Security Affairs