Overview
- Citrix confirmed active exploitation of two critical NetScaler flaws, tracked as CVE-2026-88771 and CVE-2026-88772, that allow unauthenticated remote code execution on unmitigated appliances.
- The flaws were found during incident response and forensic work and Citrix released security updates over the weekend to address the issues and several other NetScaler defects.
- CISA added the two CVEs to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by September 30, with other national CERTs issuing urgent guidance and pre-notifications.
- Citrix published generic Indicators of Compromise available via NetScaler Console but warned the IoCs may miss attacker activity and advised customers to preserve forensic evidence before applying updates.
- Operators must weigh immediate actions such as isolating or taking appliances offline because many NetScaler instances remain internet-exposed, earlier August fixes do not fix these zero-days, and the 13.1 branch recently reached End of Maintenance.