CVE-2026-88772 on NetScaler: how to verify remediation is complete
Citrix released fixes for CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway, both exploited before patches existed. Fixed builds are 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+ and 13.1-37.279+. NCSC-NL advises preserving logs and a memory dump before updating.
- Fixed builds: 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, 13.1-37.279+
- CVE-2026-88772 requires DTLS, enabled by default on VPN virtual servers
- NCSC-NL: capture logs and a memory dump before patching
- ZoomEye matched 239,201 internet-facing NetScaler assets
Read next
Security