By therecord.media
Publication Date: 2026-09-28 16:22:00
Several governments sent out urgent warnings this weekend about zero-day vulnerabilities impacting Citrix NetScaler application delivery controllers (ADC) and Gateway devices, which serve as front doors for users connecting to an organization’s environment.
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Of the eight, CVE-2026-88771 and CVE-2026-88772 have been exploited, according to Citrix. Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs.
The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal agencies until Wednesday to patch the two exploited vulnerabilities and said “forensic triage” will need to be conducted at any agency using the products.
“CISA has received…

