Citrix Confirms Exploitation of Two Critical NetScaler RCE Flaws, CVE-2026-88771 and CVE-2026-88772, as CISA Adds Both to KEV Catalog
Citrix confirmed exploitation of two critical NetScaler ADC and Gateway flaws, both CVSS v4 9.5, and shipped fixes; CISA added both to its KEV catalog as of September 27, 2026.