CISA orders feds to patch exploited Citrix flaws by Wednesday

CISA orders feds to patch exploited Citrix flaws by Wednesday
CISA has ordered U.S. federal agencies to secure vulnerable Citrix NetScaler systems after active exploitation of two critical flaws, CVE-2026-88771 and CVE-2026-88772. Citrix confirmed zero-day attacks, urged immediate patching, and warned organizations to check for compromise before updating. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #CISA #Shadowserver #CERT-EU

Keypoints

  • CISA added two Citrix NetScaler flaws to its KEV Catalog.
  • Citrix confirmed active zero-day exploitation of CVE-2026-88771 and CVE-2026-88772.
  • Both vulnerabilities can allow unauthenticated remote code execution.
  • Citrix advised checking for indicators of compromise before patching.
  • Security teams were urged to assess internet-facing NetScaler appliances immediately.

Read More: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/