Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News by The Hacker News
September 28, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 28, 2026Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerabilities are listed below –

  • CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. 
  • CVE-2026-88772 (CVSS score: 9.5) – An improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service.

While CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, CVE-2026-88772 requires the DTLS configuration to be enabled on NetScaler ADC or NetScaler Gateway, an option that is turned on by default on VPN virtual servers. The relevant configuration is as follows –


add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE 

Both the issues have been addressed in the versions below –

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

“CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said.

“Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities.”

Citrix has also made generic indicators of compromise (IoCs) available through NetScaler Console to help customers determine if their deployments have been impacted. If a compromise is suspected, customers are recommended to perform the following steps to secure their environments –

  • Preserve evidence of the NetScaler ADC VPX instance.
  • Isolate the device.
  • Revoke credentials and access.
  • Investigate all servers and systems that the NetScaler ADC had connected to for any signs of further compromise.
  • Rebuild and update the firmware to the latest version.
  • Rotate all local account passwords, Key Encryption Keys (KEK), and replace all restored SSL certificates if restoring from a known good NetScaler backup.
  • Harden the device in line with best practices.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies have been given time until September 30, 2026, to apply the fixes.



Source link

The Hacker News

The Hacker News

Next Post

Cherokee Cablevision Deploys Teleste Luminato X32 for MDU Television Delivery

Recommended.

Fed’s Hammack calls for patience in assessing what impacts tariffs will have on the economy

Fed’s Hammack calls for patience in assessing what impacts tariffs will have on the economy

April 24, 2025
Teens Are Using AI-Fueled ‘Slander Pages’ to Mock Their Teachers

Teens Are Using AI-Fueled ‘Slander Pages’ to Mock Their Teachers

March 11, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio