Trusence Every claim has a source
Last updated 28 September 2026 Search Türkçe
← All stories
Security

Citrix releases fixes for two exploited NetScaler flaws

Organizations running affected appliances can now patch them and check for signs of compromise.

Updated 28 September 2026

Citrix has issued fixes for NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 after attackers used them before public disclosure. The flaws allow unauthenticated remote code execution: the first affects NetScaler ADC and Gateway deployments with default settings, while the second requires DTLS, which is enabled by default on VPN virtual servers. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog and set September 30 as the deadline for U.S. federal civilian agencies to secure affected appliances. Citrix made generic compromise indicators available through NetScaler Console to help security teams check for breached systems. Shadowserver counted more than 23,000 internet-exposed IP addresses with NetScaler fingerprints, though that total does not show how many are still vulnerable.

Why it matters

Because attackers have already used the flaws, affected organizations face a risk that is active, not merely theoretical. Citrix’s compromise indicators give security teams a way to check their systems, while federal civilian agencies have a firm deadline to secure vulnerable appliances.

Sources

  • BleepingComputer