Citrix patches two NetScaler RCE flaws rated 9.5
Citrix released fixes on September 27, 2026, for two NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) rated 9.5 under CVSS v4. Both allowed unauthenticated remote code execution and were exploited before patches existed. Fixed releases are 14.1-73.37 and 13.1-64.23 and later.
- CVE-2026-88771 is improper input validation enabling unauthenticated command execution
- CVE-2026-88772 is a memory overflow affecting appliances with DTLS enabled
- Both flaws were exploited before a fix; no workaround or IoCs published
- ZoomEye returned 239,277 matches for Citrix NetScaler on September 30, 2026
Read next
Security