CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
CVE-2026-88771 and CVE-2026-88772 identified with evidence of active exploitation
Key Takeaways
- CISA added two Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) to the KEV Catalog based on evidence of active exploitation.
- Both vulnerabilities affect Citrix NetScaler products and represent significant risks to federal systems.
- Binding Operational Directive 26-04 requires FCEB agencies to prioritize rapid remediation of these KEV Catalog vulnerabilities on publicly exposed assets.
- CISA expects agencies to check whether threat actors compromised systems before patch application.
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.


