CISA warns that Citrix NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772 are actively exploited. The alert covers eight newly disclosed vulnerabilities in products used for application delivery and remote access.

Priority actions

  • Identify exposed NetScaler ADC and Gateway instances.
  • Apply Citrix fixes urgently, prioritizing internet-facing systems.
  • Review appliance, authentication, and administrative telemetry for anomalies.
  • Use CISA and vendor guidance for version-specific remediation.

Active exploitation makes this a patch-and-investigate event; it does not establish compromise of every deployment.

Sources: CISA; Rapid7.

By Allan