Citrix confirms two NetScaler RCE zero-days exploited in attacks
Update: Article rewritten with official confirmation from Citrix.
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.
NetScaler appliances a...
Read more at bleepingcomputer.com