Citrix NetScaler: patching CVE-2026-88772 and rollout order
Citrix published bulletin CTX697096 with fixes for NetScaler ADC and Gateway. Two flaws rated CVSS 9.5 — CVE-2026-88771 (unauthenticated command execution) and CVE-2026-88772 (DTLS memory overflow) — are already exploited; fixed builds are 14.1-73.37 and 13.1-64.23.
- CVE-2026-88771 and CVE-2026-88772 carry CVSS 9.5 and are confirmed exploited
- Fixed builds: 14.1-73.37, 13.1-64.23, FIPS 14.1-73.37, NDcPP 13.1-37.279
- Internet-facing VPN virtual servers with DTLS go first
- NCSC-NL advises capturing logs and a memory dump before updating
Read next
Security