Citrix NetScaler devices face two security flaws that are reportedly exploited in real-world attacks. Multiple outlets report that cybersecurity agencies, security researchers, and IT providers privately warned organizations to take mitigations—described as shutting down or isolating NetScaler instances—before official fixes were available.

Bleeping Computer frames the issue as a rapid-response effort in which administrators are urged to reduce exposure because two unpatched zero-days are being used. SecurityWeek, meanwhile, reports that Citrix confirms the problems and proceeds with patching, with identifiers CVE-2026-88771 and CVE-2026-88772. SecurityWeek also says the patches are issued after administrators reportedly pulled the plug as a precaution. While the outlets align on exploitation and urgency, they differ in emphasis: one focuses more on pre-patch warnings and mitigation steps, while the other highlights Citrix’s confirmation and release of the corresponding patches.

Organizations are expected to apply the updates as soon as possible to address the vulnerabilities.