NetScaler patches eight flaws, two already exploited in the wild
Citrix released fixes for eight NetScaler ADC and Gateway vulnerabilities, including CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5), both confirmed exploited. Fixed builds are 14.1-73.37 and 13.1-64.23; the NCSC urges immediate patching.
- CVE-2026-88771 (CVSS 9.5) is unauthenticated RCE affecting all ADC and Gateway deployments
- CVE-2026-88772 (CVSS 9.5) is a memory overflow with DTLS enabled, confirmed exploited
- Fixed builds: 14.1-73.37, 13.1-64.23, FIPS 14.1-73.37 and 13.1-37.279
- ZoomEye reports 239.3k internet-reachable NetScaler instances
Read next
Security