vulnerability of interest
1 TopicFAQ about CVE-2026-88771 and CVE-2026-88772: Citrix NetScaler Zero-Day RCE vulnerabilities
On September 27, Citrix published a security bulletin for two NetScaler ADC and NetScaler Gateway vulnerabilities that were exploited against unpatched customer deployments. CVE Description CVSSv4 CVE-2026-88771 Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation vulnerability 9.5 CVE-2026-88772 Citrix NetScaler ADC and NetScaler Gateway Memory Overflow vulnerability 9.5 CVE-2026-88771 affects all deployments with no additional configuration required. CVE-2026-88772 requires DTLS to be enabled, which is the default on VPN virtual servers. Both have been classified as Vulnerabilities of Interest as part of Tenable's Vulnerability Watch. For more information about these vulnerabilities, including patch versions, IoC guidance, and Tenable product coverage, please visit our blog.516Views0likes0Comments