Urgent Cybersecurity Alert: Critical Citrix NetScaler Vulnerabilities

Credit unions should promptly determine whether they or their critical technology providers use affected Citrix NetScaler products following a recent security alert from the Cybersecurity and Infrastructure Security Agency (CISA).

Citrix has issued a security bulletin addressing two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that are being actively exploited. The vulnerabilities could allow an attacker to gain access to or execute commands on affected systems.

Citrix NetScaler products are commonly used to provide secure remote access and connect users to applications and internal systems. Because these products may be accessible from the internet, a successful attack could provide an entry point into a credit union’s network or a technology provider’s environment.

Citrix has released security updates for affected customer-managed NetScaler ADC and NetScaler Gateway products and recommends installing applicable updates as soon as possible. Citrix-managed cloud services are being updated by Citrix and are not covered by the customer-managed product guidance.

Credit unions should work with their information security personnel and applicable technology providers, including managed service providers, core processors, hosted service providers, or other critical vendors, to determine whether affected products are being used.

If an affected system is identified, credit unions should:

  • Confirm that the appropriate security update has been applied.
  • Ask applicable vendors whether their environments were affected and whether remediation has been completed.
  • Assess whether there are signs that the system was compromised before the update was applied.
  • Follow established incident response procedures if suspicious activity is identified.

Patching is an important first step, but it may not address an attacker who gained access before the vulnerability was fixed. Credit unions should follow the guidance of their information security professionals and technology providers when determining whether additional investigation is necessary.

This is an urgent cybersecurity and vendor risk issue. Credit unions should determine whether they or their critical technology providers use affected Citrix NetScaler products and confirm that applicable security updates have been completed. If exposure is identified, credit unions should follow established incident response and vendor management procedures.

Read More

Written by
Katie Bailey
View all articles

About Us

The League of Credit Unions & Affiliates provides a platform for advocacy, collaboration, and innovation, representing 381 credit unions across Alabama, Florida, Georgia, and Virginia and their 32.7 million members, as well as $453.6 billion in assets. The League serves as an advocate through credit union engagement, advocacy impact, Foundation resources, and LEVERAGE products and services. Join us in supporting credit unions by learning more at www.the-league.coop. Follow The League on LinkedIn, Facebook, X, and Instagram.

Social Channels

Follow us on all major social media platforms.