Critical Citrix NetScaler Zero-Days Exploited Globally; CISA Adds to KEV
CISA KEV: Citrix NetScaler zero-days CVE-2026-88771/88772 exploited; web shells, root access. Roundcube CVE-2026-48842 also exploited. Patch now.
- CISA added two critical Citrix NetScaler ADC/Gateway flaws (CVE-2026-88771, CVE-2026-88772) to its KEV catalog after active exploitation; attackers deploy web shells, gain root, steal credentials, and move laterally.
- Internet-facing NetScaler appliances used for VPN, gateway, and remote access are the primary risk; exploitation escalated to mass scanning and spraying after a root-cause analysis and proof-of-concept exploit were published.
- Roundcube Webmail SQL injection CVE-2026-48842 (CVSS 8.1), patched four months ago, is also now exploited in the wild; unpatched webmail servers are at risk of database compromise.
What to do now
- Inventory every Citrix NetScaler ADC and Gateway instance, especially internet-facing VPN, gateway, and management interfaces; record exact versions and exposure.
- Apply Citrix patches for CVE-2026-88771 and CVE-2026-88772 immediately. If patching is not possible, isolate the appliance or restrict management and authentication interfaces to trusted networks and disable unnecessary external exposure.
- Hunt for compromise: web shells, unexpected processes, new admin accounts, configuration changes, unusual outbound connections, and authentication anomalies. Review logs from at least late last week through 29 September 2026.
- Reset credentials and rotate secrets for accounts that could have been exposed; revoke active sessions and enforce MFA. If compromise is confirmed, consider rebuilding affected appliances rather than cleanup alone.
- Patch Roundcube Webmail CVE-2026-48842, verify the version, review database and mail logs, rotate database/mail service credentials, and restrict webmail access. Follow CISA KEV timelines and vendor advisories.
Related items
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
- NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
- Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild