CVE-2026-88773 in Citrix NetScaler: a patch plan for FIPS and NDcPP
Citrix bulletin CTX697096 fixes eight flaws in NetScaler ADC and Gateway, including CVE-2026-88773 rated CVSS 9.3, which needs no authentication and only HTTP enabled. Fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1-37.279 for FIPS with NDcPP. NCSC-NL reports observed exploitation of CVE-2026-88771 and CVE-2026-88772, both rated 9.5.
- CVE-2026-88773: CVSS 9.3, no authentication, HTTP must be enabled
- Fixed builds: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1-37.279 FIPS+NDcPP
- NCSC-NL reports exploitation of CVE-2026-88771 and CVE-2026-88772 at CVSS 9.5
- ZoomEye counts 239,194 Citrix NetScaler assets exposed online
Read next
Security