News / Cybersecurity
Two Citrix NetScaler Vulnerabilities Actively Exploited Added to CISA’s KEV Catalog Published on 28 September 2026 by Christ-loisele (2 min read)
On September 27, 2026, CISA added two critical Citrix NetScaler vulnerabilities to its KEV catalog, confirming their active exploitation. These vulnerabilities, targeted by malicious actors, require an urgent response from organizations using these solutions.
The identified vulnerabilities and their risks
On September 27, 2026, CISA (Cybersecurity and Infrastructure Security Agency) announced the addition of two new vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog , due to evidence of active exploitations in the wild. These flaws, CVE-2026-88771 (described as an Improper Input Validation ) and CVE-2026-88772 (related to an Improper Restriction of Operations within the Bounds of a Memory Buffer ), specifically affect Citrix NetScaler products, widely deployed in critical infrastructures.
According to CISA, these vulnerabilities are favored attack vectors by malicious cyber actors, exposing systems to severe compromises. They are now listed among the top priorities for U.S. federal agencies, in line with the Binding Operational Directive (BOD) 26-04 , which mandates that agencies in the Federal Civilian Executive Branch (FCEB) patch vulnerabilities listed in the KEV catalog without delay.
The actively exploited vulnerabilities CVE-2026-88771 and CVE-2026-88772 require an immediate response from organizations using Citrix NetScaler to avoid severe compromises.
Illustration: Lawing Tech
Inclusion criteria and CISA recommendations
To be included in the KEV catalog, vulnerabilities must meet three strict criteria: have a CVE identifier, show tangible evidence of active exploitation, and provide clear mitigation guidelines. CISA emphasizes that federal agencies must, before patching, verify whether malicious actors have already compromised the system, to avoid ineffective measures or chain reactions.
While the BOD 26-04 directive applies only to FCEB agencies, CISA strongly encourages all organizations, regardless of sector or location, to adopt a proactive risk-based approach to vulnerability management. This recommendation aligns with a broader strategy aimed at strengthening cyber resilience against evolving threats.
What this means here
For businesses and administrations in Benin and West Africa using Citrix NetScaler solutions, this CISA announcement could serve as a warning to assess the presence of these vulnerabilities in their infrastructures. Although the BOD 26-04 directive is not binding outside U.S. federal agencies, local organizations could draw on its principles to prioritize patching critical flaws, particularly those confirmed as exploited.
For instance, Beninese public administrations could strengthen their security audits by systematically integrating KEV catalog vulnerabilities into their mitigation plans, especially if they rely on third-party solutions like Citrix NetScaler for their digital services. Collaborating with specialized cybersecurity consulting firms would help identify specific risks and apply tailored fixes before attacks occur.
Sources