
CISA Sets September 30 Deadline to Patch Actively Exploited Citrix NetScaler Zero-Day Vulnerabilities
generalcybersecurityvulnerabilitiesCISACitrixNetScalerzero-dayremote code executionCVE
CISA has set September 30 as the deadline for US federal agencies to patch two zero-day vulnerabilities in Citrix NetScaler that are already being actively exploited. The flaws are identified as CVE-2026-88771 and CVE-2026-88772. Both vulnerabilities allow remote code execution without authentication under typical deployment conditions. The US Cybersecurity and Infrastructure Security Agency issued this directive to federal agencies regarding these critical security issues in Citrix NetScaler products.