CISA has added two critical Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog after detecting active exploitation in the wild. Both flaws affect Citrix NetScaler ADC and Gateway products, widely deployed in enterprise environments worldwide.

CVE-2026-88771 carries a CVSS score of 9.5, classifying it as critical. This improper input validation vulnerability permits unauthenticated attackers to exploit the affected systems without requiring valid credentials. The flaw resides in how NetScaler processes user-supplied input, creating an entry point for remote attackers.

The inclusion on CISA's KEV catalog signals that federal agencies and critical infrastructure operators must prioritize patching. CISA maintains this list specifically to track vulnerabilities actively exploited by threat actors. Federal contractors face binding deadlines to remediate listed vulnerabilities. Private sector organizations use the catalog as a risk prioritization tool to allocate patching resources where exploitation risk remains highest.

NetScaler ADC and Gateway products serve as load balancers, firewalls, and application delivery controllers in enterprise networks. These systems often sit at network perimeters, handling traffic destined for internal applications. A compromise at this layer grants attackers direct access to backend infrastructure, lateral movement pathways, and sensitive data.

The timing of CISA's announcement follows waves of exploitation targeting NetScaler infrastructure. Prior campaigns have leveraged NetScaler flaws to establish persistent access, deploy web shells, and exfiltrate authentication credentials. Threat actors favor NetScaler compromises because the devices control network traffic and sit in trusted positions within corporate security architectures.

Organizations running NetScaler ADC or Gateway should identify affected instances immediately. Citrix published patches addressing these flaws, though patch deployment timelines vary across enterprises. The CISA alert creates urgency by establishing these vulnerabilities as active threats rather than theoretical risks.

The CVSS 9.5 rating reflects the severity of unauthenticated remote exploitation. Attackers need no special access, authentication tokens, or complex attack chains. A single network request can trigger the vulnerability. This ease of exploitation explains rapid adoption among threat actor groups.

CISA typically adds vulnerabilities to the KEV catalog within days of confirming active exploitation. The timing of this announcement indicates reconnaissance and initial compromises likely occurred weeks earlier. Defenders reviewing NetScaler logs should search for suspicious requests to known vulnerable endpoints and review firewall rules restricting NetScaler access from untrusted networks.

Organizations without current patches should implement temporary mitigations. These include restricting NetScaler management interfaces to trusted IP ranges, disabling unnecessary services, and deploying Web Application Firewalls in front of vulnerable instances. Network segmentation limiting NetScaler's reach into backend systems reduces post-compromise damage.

The second vulnerability details remain incomplete in available reporting, but its presence on the KEV catalog confirms active exploitation. Citrix customers should review all recent security advisories and patch documentation.

Remediation requires coordination across multiple teams. Network operations must prioritize NetScaler updates in change management systems. Security teams should monitor for indicators of compromise during patching windows. Incident response teams should prepare forensic procedures to detect if systems were already compromised.

The global nature of this exploitation campaign means organizations across all sectors face risk. Financial services, healthcare, government agencies, and technology companies all rely heavily on Citrix NetScaler infrastructure. CISA's alert applies the full weight of federal authority to drive remediation urgency.