https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Patch isn’t yet through QA at Citrix still, been a week
The primary vulns being exploited are 2026-88771, CVE-2026-88772, CVE-2026-88773 chained.
It gives unauth RCE in default appliance config. Attackers using it to drop webshells all month of September.