The two critical flaws
The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and both carry a CVSS score of 9.5, according to The Hacker News and Rapid7.
CVE-2026-88771 is an improper input validation bug that lets an attacker without credentials run commands on the device. Rapid7 noted that it affects vulnerable NetScaler deployments in their default configuration, with no additional product features required.
CVE-2026-88772 is a memory overflow flaw that can lead to remote code execution or denial of service. It affects appliances with DTLS enabled, which The Hacker News noted is on by default for VPN virtual servers. Rapid7 rated it as harder to exploit than the first flaw.
Citrix confirmed that both bugs had been exploited on unmitigated NetScaler deployments, according to The Hacker News. The same security bulletin covered six more flaws, CVE-2026-88773 through CVE-2026-88778, with no evidence of exploitation.