Serial number: AV26-965
Date: September 28, 2026
As of September 27, 2026, Citrix is affected by vulnerabilities in the following products:
- NetScaler ADC and NetScaler Gateway 14.1
- Prior to 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1
- Prior to 13.1-63.23
- NetScaler ADC FIPS
- Prior to 14.1-73.37 FIPS
- NetScaler ADC FIPS and NDcPP
- Prior to 13.1-37.279
On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.