Citrix shipped fixes on September 27 for NetScaler flaws CVE-2026-88771 and CVE-2026-88772, both rated 9.5 and exploited on unpatched appliances. Exploitation began before the fix, at a date Citrix has not given, so affected appliances need an intrusion check as well as an upgrade.
Perspective Coverage
17 publishers
- Builder
- Builder 12%
- Operator
- Operator 81%
- Investor
- Investor 7%
Reality
- Evidence82
- Adoption70
- Hype gap+8
- Incentives35
- Confidence78
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
watchTowr says attackers exploited CVE-2026-88771, a pre-auth command injection in default-config Citrix NetScaler, before any fix existed. Upgrading to 14.1-73.37 or 13.1-64.23 closes the hole, though a gateway exposed in that window may already have been used.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72