Citrix has confirmed that two critical NetScaler remote code execution flaws, CVE-2026-88771 and CVE-2026-88772, are being actively exploited as zero-days and has released security updates to address them. Organizations using affected NetScaler ADC and NetScaler Gateway appliances should patch immediately or reduce Internet exposure until upgrades can be completed. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772
Keypoints
- Citrix confirmed active exploitation of two critical NetScaler zero-days.
- CVE-2026-88771 allows unauthenticated remote code execution through improper input validation.
- CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is enabled.
- Affected products include NetScaler ADC, NetScaler Gateway, and certain Secure Private Access Hybrid deployments.
- Citrix released patches and organizations should upgrade or reduce exposure immediately.