CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Citrix has a support base article, confirming exploitation. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Shoutout to the folks on that Citrix subreddit thread, the security researchers validating the bugs, and the random IT teams who proactively reached out to affected NetScaler customers over the weekend, all of whom did a far better job at mitigating the damage before Citrix joined the party.