NetScaler admins told to patch critical zero-days in ADC and Gateway now
“ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday.

“ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday.
The short version
- Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both.
- Affected customers should install the patched versions “as soon as possible,” Citrix wrote in an advisory issued later on Sunday.
- NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services.
What happened
Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available.
Why it matters
CVE-2026-88771 is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation.
Summary by Nerd News Network. Read the full article at Network World via the links above and below.
