Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S.