Citrix Issues Emergency Fixes for Two Actively Exploited NetScaler Zero-Days

Citrix has released emergency security updates for two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, are already being exploited in real-world attacks and each has a CVSS v4.0 score of 9.5. They can permit unauthenticated remote code execution on vulnerable appliances.
Related stories
CISA sets Wednesday deadline for federal agencies to fix actively exploited Citrix NetScaler bugs · Cybersecurity
CISA flags active exploits in SharePoint and MikroTik RouterOS · Cybersecurity
Also covered by: Viakoo, Inc
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “CVE-2026-88771 and CVE-2026-88772: Critical Citrix NetScaler Zero-Days Exploited in the Wild.” Browse more stories.