Follow the latest coverage, related explainers and connected technology stories.
Attackers exploited two zero-day vulnerabilities in Citrix NetScaler appliances to install PHP backdoors and a network tunneling tool, gain root privileges, steal credentials, and move within networks. Citrix released security updates, while Mandiant warned that disabling DTLS addresses only one of the vulnerabilities.
CISA added the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 to its catalog of exploited vulnerabilities and gave U.S. civilian federal government agencies until September 30 to secure the affected devices. The two vulnerabilities enable unauthenticated remote command execution, while Citrix warned that indicators of compromise may not reveal all cases of compromise.
Citrix confirmed that two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway are actively being exploited in attacks and released updates to address them. The first vulnerability affects all deployments, even with default configurations, while the second is linked to DTLS being enabled, which is enabled by default on VPN virtual servers.