The Cybersecurity and Infrastructure Security Agency on Sunday warned that critical zero-day vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway are facing exploitation and need to be immediately addressed.
The agency later added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog.
Citrix said the bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway.
The company urged security teams to review the guidance to determine whether certain preconditions were met on NetScaler deployments before applying upgrades.
For example, preconditions for CVE-2026-88772 are met only when datagram transport layer security (DTLS) is enabled on NetScaler ADC or NetScaler Gateway.