cisaregulatorNewsThe Broadside2 min read

CISA Adds Two Critical NetScaler Zero-Days to KEV Catalog

The KEV listing means active exploitation is confirmed, and organizations that patch before checking for compromise risk losing forensic evidence of an intrusion already in progress.


TL;DR

CISA added CVE-2026-88771 and CVE-2026-88772 (two critical remote-code-execution vulnerabilities in Citrix NetScaler ADC and Gateway) to its Known Exploited Vulnerabilities catalog. Both are zero-days; CISA has received reports and partner threat intelligence confirming threat actors are actively exploiting them globally. The alert covers eight total CVEs in the same product line. Citrix has published indicators of compromise and guidance for assessing potential compromise before applying updates, since patching may destroy forensic evidence.

CISA's alert amplifies Citrix's disclosure of eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway: CVE-2026-88771 through CVE-2026-88778. Two of them (CVE-2026-88771 and CVE-2026-88772) have been added to the KEV catalog. Both are critical zero-days that can independently enable remote code execution, and CISA has confirmed through reports and partner threat intelligence that they are under active global exploitation.

The KEV designation is not a formality. It's CISA's way of telling network defenders that these aren't theoretical, someone is using them right now. The remaining six CVEs in the bulletin don't yet carry that designation, but organizations running NetScaler ADC or Gateway should treat the entire bulletin as urgent.

The forensic catch

CISA is telling organizations to check for indicators of compromise before patching, not after. The reason is straightforward: applying the updates may result in loss of forensic visibility. If an attacker already has a foothold, patching over the entry point without first collecting evidence means you lose the ability to determine what happened, what was taken, and whether the adversary moved laterally. Citrix has made indicators of compromise available through NetScaler Console, and the company's security bulletin includes additional guidance on compromise assessment.

Trade-offs that bite

NetScaler patching isn't always a quick maintenance window. The complexity and potential downtime involved mean security teams will face real prioritization calls, especially shops managing multiple appliances across production, staging, and DR environments. The KEV listing doesn't set a BOD 22-01 remediation deadline in this specific alert, but the operational calculus is the same: every hour an unpatched appliance stays exposed is an hour an active exploit chain can fire.

The pattern isn't new. CVE-2023-3519 and CVE-2023-4966 (Citrix Bleed) both demonstrated how quickly NetScaler vulnerabilities become vectors for webshells, credential theft, and in the case of Bleed, LockBit 3.0 affiliate activity documented in a joint advisory from CISA, FBI, and international partners in November 2023. Organizations that assume they haven't been hit because they haven't noticed anything unusual should recall that the 2023 incidents involved adversaries who maintained access for weeks before detection, and in at least one case, network segmentation was the only thing that stopped lateral movement to a domain controller.

What to do Monday

Review Citrix's security bulletin for the full list of affected versions and patch availability. If you can, run the indicators of compromise through NetScaler Console before touching anything. If compromise is suspected, preserve forensic evidence before applying updates. If no compromise is detected, patch immediately. And if you're in the federal supply chain, assume this will surface in contract security reviews and third-party risk assessments within the week.


Published ·Deep Fathom