Citrix discloses eight NetScaler vulnerabilities, two already exploited
Citrix published bulletin CTX697096 on September 27, 2026, covering eight NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Two are already being exploited: an unauthenticated command-execution flaw and a DTLS memory-overflow bug. CISA added both to its Known Exploited Vulnerabilities catalog with a September 30 remediation deadline.
- Bulletin CTX697096 covers CVE-2026-88771 through CVE-2026-88778
- CVE-2026-88771 is unauthenticated command execution in default config
- CVE-2026-88772 requires DTLS, on by default for VPN virtual servers
- Mandiant: campaign against CVE-2026-88772 ongoing since at least early September
Read next
Security