ORBITRUM← Back to Signals

Citrix · security

Citrix Patches Two Actively Exploited NetScaler Zero-Days

Citrix confirmed that two 9.5-severity NetScaler remote-code-execution flaws were exploited before disclosure and released fixes for affected customer-managed appliances.

By Orbitrum
Security alert graphic centered on Citrix NetScaler infrastructure, showing two actively exploited remote-code-execution vulnerabilities with a 9.5 severity score and an update symbol, highlighting risk to internet-facing enterprise edge systems.

Is every NetScaler deployment affected?

CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, while CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers.

Orbitrum Investor Impact

Why does this matter for Citrix's business?

NetScaler appliances commonly sit at the network edge for remote access and application delivery, so successful exploitation can give attackers a foothold into customer networks. The sources checked do not quantify any resulting revenue, cost, or customer-loss impact for Citrix.

Are Citrix-managed cloud services covered by the same vulnerability bulletin?

No. The bulletin applies to customer-managed NetScaler ADC and Gateway deployments; Cloud Software Group says it is applying the necessary updates to Citrix-managed cloud services and Adaptive Authentication.

Are fixes available now?

Yes. Citrix recommends upgrading immediately to NetScaler 14.1-73.37 or 13.1-64.23 and later releases in those branches, with corresponding fixed FIPS and NDcPP builds also available.

What happens next?

Customers need to patch affected appliances and investigate for signs of compromise. Citrix has made indicator-of-compromise scanning available through NetScaler Console and says its detection logic may be updated as additional indicators emerge.

Sources

Original signal: BleepingComputer ↗

See more Orbitrum in Google

Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.