Citrix confirms two NetScaler RCE zero-days exploited in attacks
Another weekend, another “shut down your NetScalers” advisory. Citrix confirmed two zero-days already exploited in the wild: CVE-2026-88771 (CVSS 9.5) gives an unauthenticated attacker command execution in default configurations, and CVE-2026-88772 hits memory when DTLS is enabled, which it is by default on VPN servers. Fixed in 14.1-73.37 and 13.1-64.23. Can’t patch today? Cut the internet exposure.