Citrix has confirmed active exploitation of CVE-2026-88771, a remote code execution flaw with no prerequisites, and CVE-2026-88772, a DTLS memory overflow. Both are rated CVSS 9.5 and both are now on CISA’s Known Exploited Vulnerabilities list. Six more zero-day flaws rated between 7.0 and 9.3 were fixed in the same release. The fixed builds are 14.1-73.37 and 13.1-64.23 (FIPS and NDcPP builds have their own fix, 13.1-37.279), and ASD has advised organisations to install the update and review device logs.
NetScaler sits exactly where attackers want to be: on the internet, in front of remote access, trusted by everything behind it. We’ve written this story before about Fortinet and Cisco. The edge appliance is the preferred front door, and the gap between disclosure and mass exploitation is now measured in days.
If you run NetScaler — or someone runs it for you — confirm the build number today. Patching closes the hole; it doesn’t remove anyone who got in first, so review the logs and reset credentials and sessions that passed through the gateway. Longer term, it’s the same question we keep asking: does remote access need a box on the internet at all, or can identity-based access such as Azure Virtual Desktop behind Conditional Access replace it?
