Citrix · security
Citrix Patches Two Actively Exploited NetScaler Zero-Days
Citrix confirmed that two 9.5-severity NetScaler remote-code-execution flaws were exploited before disclosure and released fixes for affected customer-managed appliances.
Is every NetScaler deployment affected?
CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments, while CVE-2026-88772 requires DTLS, which is enabled by default on VPN virtual servers.
Orbitrum Investor Impact
Why does this matter for Citrix's business?
NetScaler appliances commonly sit at the network edge for remote access and application delivery, so successful exploitation can give attackers a foothold into customer networks. The sources checked do not quantify any resulting revenue, cost, or customer-loss impact for Citrix.
Are Citrix-managed cloud services covered by the same vulnerability bulletin?
No. The bulletin applies to customer-managed NetScaler ADC and Gateway deployments; Cloud Software Group says it is applying the necessary updates to Citrix-managed cloud services and Adaptive Authentication.
Are fixes available now?
Yes. Citrix recommends upgrading immediately to NetScaler 14.1-73.37 or 13.1-64.23 and later releases in those branches, with corresponding fixed FIPS and NDcPP builds also available.
What happens next?
Customers need to patch affected appliances and investigate for signs of compromise. Citrix has made indicator-of-compromise scanning available through NetScaler Console and says its detection logic may be updated as additional indicators emerge.
Sources
- Citrix — Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
- BleepingComputer — Citrix confirms two NetScaler RCE zero-days exploited in attacks
- Citrix Community — Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Original signal: BleepingComputer ↗
See more Orbitrum in Google
Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.