Overview
- Citrix disclosed on Sunday that two critical NetScaler zero-days, now tracked as CVE-2026-88771 and CVE-2026-88772, were exploited in the wild and the company released fixes for affected 14.1 and 13.1 builds.
- CVE-2026-88771 is an unauthenticated input-validation flaw that allows remote code execution and CVE-2026-88772 is a DTLS-related memory overflow that can cause remote code execution or denial of service.
- Citrix published updated builds (including 14.1-73.37 and 13.1-64.23) and added a generic IoC scan in NetScaler Console starting with 14.1-73.36, but the vendor warns those detections require telemetry and may miss attacker techniques.
- Before the public advisory, administrators, CERTs and IT suppliers privately urged organizations to isolate or take NetScaler appliances offline, and earlier August fixes do not address these new zero-days.
- Because NetScaler devices sit at the network edge and attackers can keep access after a breach, Citrix and national CSIRTs advise preserving evidence, running forensic reviews, rotating credentials and seeking expert help rather than relying on patching alone.