CISA adds two Citrix NetScaler flaws to KEV catalog
On September 27, 2026, CISA added two Citrix NetScaler vulnerabilities with evidence of active exploitation to its KEV catalog and urged organizations to prioritize risk-based remediation.
On September 27, 2026, CISA announced the addition of CVE-2026-88771, an improper input validation flaw, and CVE-2026-88772, an improper restriction of operations within the bounds of a memory buffer flaw, both affecting Citrix NetScaler. The agency reported evidence of active exploitation. The KEV catalog lists vulnerabilities known to have been exploited.
Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize high-risk KEV vulnerabilities on publicly exposed assets where exploitation could grant full control, and sets expectations for checking for possible compromise before patching. Though the directive applies to those agencies, CISA encourages all organizations to use risk-based vulnerability management. Consult CISA’s original alert and catalog entry to verify details and mitigation guidance; the agency says submissions for possible catalog inclusion should provide a CVE identifier, exploitation evidence, and clear mitigation.