Skip to content
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation

Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation

First seen 26 Sep 2026, 21:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 20:59 UTC
  • •Two critical zero-day vulnerabilities in Citrix NetScaler are actively exploited.
  • •CVE-2026-88771 and CVE-2026-88772 allow remote code execution with a CVSS score of 9.5.
  • •Citrix has released patches for the vulnerabilities on September 27, 2026.

On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, with severity scores of 9.5. The vulnerabilities were discovered during forensic investigations, indicating they were exploited before any patch was available. Administrators were advised to shut down their NetScaler appliances as a precaution. Citrix has since released a security bulletin detailing these flaws and provided patches on September 27, 2026. The vulnerabilities affect all NetScaler ADC and Gateway deployments, including those with default configurations. Organizations using these systems are urged to apply the updates immediately to mitigate the risk of exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 21h ago How this analysis works

Timeline

2019-12-27
CVE-2019-19781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-10
CVE-2023-4966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-27
Public exploit for CVE-2025-5777 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2025-06-17
CVE-2025-5349 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-25
CVE-2025-6543 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-23
CVE-2026-3055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
CVE-2026-35273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-8452 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-8451 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-65660 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (100)

Following this threat?

Track Unc6240, Sideeye and Citrix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed