Technology
Citrix patches two NetScaler zero-days that attackers were already exploiting
Citrix has released fixes for two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers were already exploiting before a patch existed. The first, CVE-2026-88771, is rated 9.5 under CVSS v4, needs no authentication and no special feature to reach, and gives an attacker a way to run commands of their choosing; the second, CVE-2026-88772, is a memory overflow that could allow code execution or take a service down.