Two serious security flaws in Citrix NetScaler ADC and Gateway are being actively exploited by attackers right now, and Citrix has released urgent patches.
- What it is: Two critical vulnerabilities (CVE-2026-88771 and CVE-2026-88772) let an attacker remotely take control of an unpatched NetScaler device without needing a password.
- Who is affected: Any business running NetScaler ADC or Gateway versions before 14.1-73.37 or 13.1-64.23, including the FIPS editions. These devices are commonly used for secure remote access and load balancing.
- What the risk is: Attackers are already exploiting these flaws in the wild to gain full control of affected appliances, putting the whole connected business network at risk.
- What action is needed: Apply Citrix's security updates immediately. If patching cannot happen right away, reduce internet exposure to the device until it is updated.
If your business uses NetScaler for remote access or load balancing, we recommend confirming with your IT provider today that these patches have been applied.
Source: BleepingComputer