# Citrix issues fixes for NetScaler flaws reported under active attack

_Published Monday, September 28, 2026 at 9:20 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Citrix issues fixes for NetScaler flaws reported under active attack — Primary](https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/5/1/7/2/2/0/6/shutterstock_2692522213-b1abab9d01837c71.jpg?func=bound&height=1200&org_if_sml=1&q=85&width=1200)

Citrix has issued an advisory and fixes for critical NetScaler vulnerabilities after security researchers reported exploitation in the wild, heise reported. Two flaws, CVE-2026-88771 and CVE-2026-88772, allow remote code execution; the first affects default configurations. A third critical flaw affects NetScaler ADC or Gateway instances with HTTP enabled. The US cybersecurity agency CISA has listed exploited vulnerabilities and issued an alert.

Citrix has listed replacement NetScaler OS versions 13.1-64.24 and 14.1-37.73 on its download page for customers. Support representatives described an early access build as unfinished and warned that it could contain bugs or other defects, leaving administrators to weigh that risk against the reported attacks.

## Sources

- [heise.de](https://www.heise.de/en/news/Security-researchers-warn-New-zero-day-exploits-in-Citrix-Netscaler-11467269.html)

---
Canonical: https://techandbusiness.org/newswire/3df6t9L8ihirAS7kkE92pD
Published: 2026-09-28T13:20:11.944Z
Story chronology: 2026-09-27T11:50:00.000Z
Retrieved: 2026-09-28T14:53:24.058Z
Publisher: Tech & Business (techandbusiness.org)
