Citrix has warned that exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated NetScaler deployments. The vendor’s security bulletin covers multiple NetScaler ADC and Gateway vulnerabilities, with the two actively exploited issues demanding immediate attention from organizations that operate affected appliances.

Internet-facing application-delivery and gateway systems often sit on critical access paths, so remediation should begin with an accurate inventory of exposed NetScaler instances and their versions. Apply Citrix’s fixed releases and configuration guidance, then verify the change. A patch alone is not proof that an earlier intrusion did not occur; environments that were exposed before remediation should be assessed for signs of compromise.

Security teams should retain relevant logs, review administrative and network activity for anomalies, rotate credentials where evidence or risk warrants it, and validate that external access is limited to intended services. The bulletin also describes deployment preconditions for several listed issues, which can help teams prioritize assessment. Follow the vendor’s current guidance rather than relying on summaries, as affected builds and remediation details may change.

Source: Citrix security bulletin CTX697096.

By Allan