AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 28 Sept, 12:59

Citrix reports exploitation of two critical NetScaler flaws

Citrix observed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated customer-managed deployments. CERT-EU recommends compromise checks for exposed affected appliances.

Citrix disclosed multiple vulnerabilities in customer-managed NetScaler ADC and Gateway on September 27, including two critical remote-code-execution flaws, CVE-2026-88771 and CVE-2026-88772. The company reports observing exploitation of both flaws on unmitigated deployments. Their configuration conditions differ: the first affects affected deployments generally, while the second requires DTLS to be enabled. Citrix lists standard fixed builds 14.1-73.37 and 13.1-64.23 for supported systems, with separate fixed versions for FIPS and NDcPP. Operators should identify their affected product and branch before updating. CERT-EU recommends a compromise assessment for internet-facing appliances running an affected build. That recommendation does not establish that every exposed appliance was compromised.

#Citrix#NetScaler#CVE-2026-88771#CVE-2026-88772