Khabar 24h SIMPLE EXPLAINERS ON WORLD AFFAIRS, SCIENCE, HEALTH AND MORE.

KHABAR 24H

Simple explainers on world affairs, science, health and more.

All news under one minute

Cybersecurity & Privacy Read in one minute

Citrix confirms two exploited NetScaler zero-days, issues patches

Citrix published emergency security bulletin CTX697096 on Sunday, covering two zero-day flaws in NetScaler ADC and NetScaler Gateway, after confirming that attacks exploiting both vulnerabilities had been observed in the wild.

The flaws are tracked as CVE-2026-88771 and CVE-2026-88772, each carrying a CVSS v4 score of 9.5. The first is an unauthenticated remote code execution flaw caused by improper input validation in default configurations. The second is a memory overflow reachable through DTLS traffic that can enable remote code execution or denial of service.

The flaws surfaced publicly through a September 25 post on r/Citrix citing a leaked Dutch NCSC-NL pre-notification. WatchTowr disclosed two distinct zero-days on September 26, and the Dutch agency advised shutting down NetScaler systems before patches existed. This is the third round of emergency NetScaler patches since June 2026.

CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 27 and invoked Binding Operational Directive 26-04 for federal agencies. Emergency patch builds are 14.1-73.37 and 13.1-64.23 or later. Administrators running the August builds should upgrade, as those do not include these fixes.

Avatar photo
Written by
Khabar 24h Editorial Desk

Khabar 24h Editorial Desk — our explainers are prepared by the Khabar 24h editorial team using AI-assisted research tools, and every piece is reviewed by a human editor before publishing. We do not claim original reporting: our work is turning complex topics into simple, accurate summaries. Spotted an error? Write to contact@khabar24h.com — our corrections policy aims for same-day review.

More from this author →

Leave a Reply

Your email address will not be published. Required fields are marked *