TWO unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway were exploited as zero-days for weeks, according to Datawater. The CVEs are CVE-2026-88771 and CVE-2026-88772, both rated with CVSS 9.5, and the exploits were widely observed before patches existed. The exploits have led to the inclusion of these CVEs in the U.S.
Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, with federal guidance stressing urgent remediation and forensic triage.
By 30 September 2026, organisations were urged to upgrade to fixed releases: 14.1-73.37 or 13.1-64.23, with the FIPS/NDcPP line listed as 13.1-37.279. The situation implies that patching alone may not reveal whether a breach has already occurred, raising the importance of post-exploit hunting and investigation.
In practical terms, the report notes that as many as 50,000 devices may have remained exposed during the window of exploitation, underscoring the need for immediate asset discovery, credential review, and traffic analysis in affected environments. The article highlights the severity of the incident and the necessity for rapid upgrade combined with proactive compromise assessment to limiting continuing risk.