CISA gives federal agencies until Saturday to patch actively exploited Citrix NetScaler flaw
CISA has added a Citrix NetScaler remote code execution vulnerability to its Known Exploited Vulnerabilities catalog, giving U.S. federal civilian agencies a tight deadline to patch affected appliances. The agency confirmed the flaw is being actively exploited in the wild, which is why the directive comes with a hard Saturday cutoff rather than the usual multi-week window.
NetScaler devices are widely used as load balancers and VPN gateways sitting at the edge of corporate and government networks, making them a prime target: successful exploitation can hand attackers a foothold deep inside otherwise well-defended infrastructure. Citrix has released patches, and CISA's binding operational directive applies specifically to federal agencies, though the underlying risk extends to any organization running unpatched NetScaler instances.
Security teams outside government should treat this with equal urgency, since public disclosure and active exploitation typically accelerate copycat attacks against laggard networks.