Site icon VMVirtualMachine.com

Citrix Patches Critical Zero Days Under Active Exploitation

Citrix Patches Critical Zero Days Under Active Exploitation

By Phil Muncaster
Publication Date: 2026-09-28 08:30:00

Citrix has published updates for eight new vulnerabilities, including two critical zero-day CVEs that had been under active exploitation.

In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). They have CVSS scores ranging from 7 to 9.5.

The two most urgent are:

  • CVE-2026-88771: a remote code execution (RCE) flaw due to improper input validation, enabling an unauthenticated attacker to execute arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments with default configuration
  • CVE-2026-88772: a memory overflow vulnerability leading to RCE or denial of service. It affects any deployment with DTLS configuration enabled (which it is by default on VPN vServers)

“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” Citrix said in a blog post. “Citrix strongly urges affected…

Exit mobile version