Citrix, a software company that provides networking and cloud services, issued emergency updates on September 27 for two of its NetScaler products, addressing eight critical vulnerabilities. Administrators using these systems are strongly advised to install the updates immediately, as two of the flaws are already being exploited by attackers. This is the third time in a few months that NetScaler products have been found to have vulnerabilities that are actively being used in attacks. According to Citrix, there are no workarounds or temporary fixes for these flaws; the only way to secure the systems is to apply the updates and then check if they have already been compromised. The most severe of the two actively exploited flaws is CVE-2026-88771, which is a problem with how the system validates input data. This flaw allows an attacker to run arbitrary commands on the system without needing to authenticate. It has a CVSS score of 9.5 out of 10, which is very close to the maximum possible score. This vulnerability affects all versions of NetScaler ADC and NetScaler Gateway, including the default configurations, without requiring any specific features to be enabled. Therefore, checking the system's configuration is not useful—only the version of the software installed matters. The second flaw, CVE-2026-88772, is a memory overflow vulnerability, also with a CVSS score of 9.5. It could allow an attacker to execute arbitrary code or cause a denial of service. Unlike the first flaw, this one requires that a feature called DTLS be active, which is the default setting. A gateway is vulnerable if DTLS has not been disabled using the -dtls OFF option, and other virtual servers are vulnerable if they are of the DTLS type, according to Citrix. In addition to these two critical flaws, the updates also address six other vulnerabilities, including one with a CVSS score of 9.3. This flaw, CVE-2026-88773, involves an issue with how the system handles HTTP requests, which could allow an attacker to smuggle requests through the system. While it is slightly less severe than the first two, it does not appear to be actively exploited. The other vulnerabilities have CVSS scores ranging from 7 to 8.8, which still indicates they are of significant severity. Security experts emphasize that installing the patches is essential but not sufficient. The updates prevent future attacks but cannot fix damage caused by existing exploits. Affected organizations are advised to keep system memory images and logs for at least a month after applying the updates and to monitor the systems closely afterward. They should also look for signs of compromise using tools provided by Citrix or third-party cybersecurity firms. However, Citrix warns that these tools might not detect all types of attacks, and additional steps such as updating secrets and reducing internet exposure are also recommended.