# CISA Mandates Citrix NetScaler Patching

The Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 26-04 requiring all federal civilian agencies to mitigate two critical zero-day remote code execution vulnerabilities actively exploited in Citrix NetScaler ADC and Gateway appliances by September 30, 2026. These vulnerabilities have been added to CISA's Known Exploited Vulnerabilities Catalog, underscoring the urgency for agencies to patch or discontinue affected systems immediately to protect critical infrastructure. The directive also calls for forensic investigations to assess potential compromises. This action highlights the increasing emphasis on rapid vulnerability response and vendor transparency in federal cybersecurity procurement and risk management.

- **Why this matters:** Federal procurement professionals must prioritize acquisition and deployment of updated Citrix NetScaler products or alternative solutions compliant with CISA directives to maintain operational security.
- Agencies should evaluate existing contracts with Citrix and related cybersecurity service providers to ensure timely patch management and incident response capabilities.
- Contractors supporting federal IT infrastructure need to align their cybersecurity offerings with CISA mandates, emphasizing rapid vulnerability mitigation and forensic readiness.
- This directive signals heightened federal scrutiny on vendor disclosure practices and may influence future procurement requirements for cybersecurity transparency and responsiveness.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 29, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)

### Vendors
- Citrix (product vendor)
- Palo Alto Networks (security researcher)
- Mandiant Consulting (security researcher)
- Coalition (insurance carrier)

### Key Quotes
> I fully understand a vendor embargoing specific details about a vulnerability when a patch has not yet been published, but once the vuln is exploited in the wild, some of those rules no longer apply.
> — Joe Toomey, Vice President of Underwriting at Coalition

### Sources
- [Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings | CyberScoop](https://cyberscoop.com/citrix-zero-days-delayed-disclosure) - CyberScoop
- [CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks](https://cybersecuritynews.com/citrix-netscaler-0-day-rce-vulnerabilities-exploited/amp) - CyberSecurityNews