Citrix disclosed CVE-2026-88771 and CVE-2026-88772, both scoring 9.5 on the CVSS scale, affecting default configurations of its NetScaler ADC and Gateway products. Citrix confirmed exploits against unmitigated deployments and urged customers to patch immediately, though public warnings of attacks had circulated online since September 25, days before the formal disclosure.
darkreading.com
· 2026-09-29
CISA has directed federal agencies to fix two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that Citrix confirmed are being actively exploited in zero-day attacks. Both bugs let unauthenticated attackers achieve remote code execution, with the first hitting default configurations and the second requiring DTLS, which is on by default for VPN virtual servers. Citrix has issued patches and shared indicators of compromise, after agencies like the Dutch NCSC had already been privately warning organizations to shut down affected appliances.
bleepingcomputer.com
· 2026-09-28