Actively Exploited NetScaler and Exchange Flaws Put School Edge Infrastructure at Risk

CISA adds exploited Citrix NetScaler CVE-2026-88779 to KEV; Microsoft patches Exchange CVE-2026-96940; WordPress plugin XSS exploited. K-12 guidance.

  • CISA added CVE-2026-88779 (CVSS 8.7), a memory overflow in Citrix NetScaler ADC and Gateway, to its Known Exploited Vulnerabilities catalog after Citrix confirmed targeted zero-day attacks that can crash appliances and knock SAML single sign-on offline.
  • Microsoft released out-of-band Exchange Server updates for CVE-2026-96940, a high-severity flaw letting an authenticated attacker read other users' mail and attachments within the same organization.
  • Separately, stored XSS in the WordPress plugins Ninja Forms and WPC Product Bundles for WooCommerce is being exploited to plant backdoors and create rogue administrator accounts; no CVE identifiers were available at reporting time.

What to do now

  1. Inventory every Citrix NetScaler ADC and NetScaler Gateway instance, record its version and internet exposure, then apply the latest Citrix security updates as an emergency change. If patching is not immediately possible, restrict management interfaces to trusted internal networks or VPN-only access and enable Citrix's recommended mitigations.
  2. Apply Microsoft's out-of-band Exchange Server update for CVE-2026-96940 to all servers, prioritizing internet-facing and hybrid deployments, then verify the installed build and restart services as required.
  3. Hunt for exploitation on both platforms: NetScaler logs for crashes, memory exhaustion, unexpected restarts and SAML authentication anomalies; Exchange logs for unusual same-organization mailbox and attachment access. Rotate credentials, tokens, certificates and secrets that transited or were stored on affected appliances.
  4. Update the Ninja Forms and WPC Product Bundles plugins, audit WordPress for unauthorized administrator or editor accounts, remove them, rotate admin passwords and salts, and scan mu-plugins, uploads, wp-config.php, cron events and database options for backdoors.
  5. Prepare continuity before you need it: configure a SAML fallback or manual authentication path, document manual traffic redirection, test backups and restoration, and report any confirmed compromise to your security team and privacy office.

Related items