Critical Citrix NetScaler Zero-Days Exploited Globally; CISA Adds to KEV

CISA KEV: Citrix NetScaler zero-days CVE-2026-88771/88772 exploited; web shells, root access. Roundcube CVE-2026-48842 also exploited. Patch now.

  • CISA added two critical Citrix NetScaler ADC/Gateway flaws (CVE-2026-88771, CVE-2026-88772) to its KEV catalog after active exploitation; attackers deploy web shells, gain root, steal credentials, and move laterally.
  • Internet-facing NetScaler appliances used for VPN, gateway, and remote access are the primary risk; exploitation escalated to mass scanning and spraying after a root-cause analysis and proof-of-concept exploit were published.
  • Roundcube Webmail SQL injection CVE-2026-48842 (CVSS 8.1), patched four months ago, is also now exploited in the wild; unpatched webmail servers are at risk of database compromise.

What to do now

  1. Inventory every Citrix NetScaler ADC and Gateway instance, especially internet-facing VPN, gateway, and management interfaces; record exact versions and exposure.
  2. Apply Citrix patches for CVE-2026-88771 and CVE-2026-88772 immediately. If patching is not possible, isolate the appliance or restrict management and authentication interfaces to trusted networks and disable unnecessary external exposure.
  3. Hunt for compromise: web shells, unexpected processes, new admin accounts, configuration changes, unusual outbound connections, and authentication anomalies. Review logs from at least late last week through 29 September 2026.
  4. Reset credentials and rotate secrets for accounts that could have been exposed; revoke active sessions and enforce MFA. If compromise is confirmed, consider rebuilding affected appliances rather than cleanup alone.
  5. Patch Roundcube Webmail CVE-2026-48842, verify the version, review database and mail logs, rotate database/mail service credentials, and restrict webmail access. Follow CISA KEV timelines and vendor advisories.

Related items