CISA orders US federal agencies to patch critical Citrix flaws
The Cybersecurity and Infrastructure Security Agency issued orders over the weekend of 28 September 2026 directing all US government agencies to patch two critical Citrix NetScaler vulnerabilities by Wednesday. The flaws are being actively exploited in attacks.