The Maivia Gazette

Verified AI news, every morning

Security

Citrix confirms two NetScaler zero-days exploited in attacks, and CISA orders federal agencies to patch by Wednesday

Both flaws allow unauthenticated remote code execution, and one affects appliances in their default configuration. Before Citrix released patches, national agencies and IT suppliers had privately told administrators to shut their appliances down.

Network appliances at a data center perimeter at night, with unplugged cables and amber warning lights.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Over the weekend, Citrix confirmed that attackers are exploiting two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, CVE-2026-88771 and CVE-2026-88772, and released patches. Both carry a CVSS score of 9.5, according to SecurityWeek. CVE-2026-88771 lets an unauthenticated attacker execute code remotely and affects all deployments, including those in the default configuration. CVE-2026-88772 is a memory overflow that can lead to code execution or denial of service on appliances with DTLS enabled, which Citrix says is the default on VPN virtual servers. The advisory covers eight vulnerabilities in total, and Citrix has published indicators of compromise. Help Net Security reports that the two zero-days were used to plant webshells. The first signs came on Reddit, where administrators said IT suppliers, CERT teams and security providers had told them to shut down their appliances immediately. Some of those warnings traced back to the Dutch National Cyber Security Center. Researcher Kevin Beaumont said the attacks had been going on all month and were 'probably nation state aligned.' Tenable noted that no threat actor has been publicly identified. CISA has added both flaws to its Known Exploited Vulnerabilities catalog and ordered US federal agencies to secure their systems by Wednesday. NetScaler appliances usually sit at the network edge and provide remote access, so a compromised device can give an attacker a foothold into internal systems.

Sources

  1. BleepingComputerCitrix confirms two NetScaler RCE zero-days exploited in attacksPublished · fetched
  2. BleepingComputerCISA orders feds to patch exploited Citrix flaws by WednesdayPublished · fetched
  3. SecurityWeekCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugPublished · fetched
  4. Help Net SecurityCitrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net SecurityPublished · fetched
  5. Security AffairsCitrix Confirmed Two New NetScaler Flaws Exploited as Zero-DayPublished · fetched
  6. Security AffairsU.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogPublished · fetched
  7. The Hacker NewsCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws GloballyPublished · fetched

Also in this edition