started · updated
Citrix releases urgent patches for exploited NetScaler vulnerabilities
Citrix has released critical security updates to address eight vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. At least two of these flaws, identified as CVE-2026-88771 and CVE-2026-88772, were confirmed to have been actively exploited in the wild as zero-day vulnerabilities before patches were available.
CVE-2026-88771 is a high-severity remote code execution (RCE) vulnerability with a CVSS score of 9.5. It allows unauthenticated attackers to execute arbitrary commands in default configurations. CVE-2026-88772 is also rated 9.5 and involves a memory overflow that can lead to RCE or denial of service when DTLS is enabled.
Global cybersecurity agencies have responded to the threat. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities catalogue, and the Australian Cyber Security Centre (ACSC) issued a critical alert urging organizations to apply updates and monitor device logs for suspicious activity. Security researchers, including those from watchTowr, noted that the vulnerabilities were identified during forensic investigations into active attacks.
Entities
Australian Cyber Security Centre · Citrix · Cybersecurity and Infrastructure Security Agency · National Cyber Security Centre · NetScaler · Tenable · WatchTowr
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] The Australian Cyber Security Centre issued a critical alert regarding eight vulnerabilities in Citrix NetScaler products. www.govtechreview.com.au · www.technologydecisions.com.au · www.itnews.com.au
- [● 4 SOURCES] CVE-2026-88771 is a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands in default configurations. www.archynewsy.com · www.govtechreview.com.au · www.itnews.com.au
- [● 4 SOURCES] Citrix released security updates to address eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products. www.archynewsy.com · www.govtechreview.com.au · www.itnews.com.au
- [○ 1 SOURCE] The U.S. Cybersecurity and Infrastructure Security Agency added the NetScaler flaws to its Known Exploited Vulnerabilities catalogue. www.itnews.com.au
- [● 2 SOURCES] CVE-2026-88772 is a memory overflow vulnerability that enables remote code execution or denial of service when DTLS is enabled. www.archynewsy.com · www.itnews.com.au
- [● 3 SOURCES] Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before patches were released. www.archynewsy.com · securityaffairs.com · www.itnews.com.au