Cyberkendra Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation
Article Content
- •Two critical zero-day vulnerabilities in Citrix NetScaler are actively exploited.
- •CVE-2026-88771 and CVE-2026-88772 allow remote code execution with a CVSS score of 9.5.
- •Citrix has released patches for the vulnerabilities on September 27, 2026.
On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, with severity scores of 9.5. The vulnerabilities were discovered during forensic investigations, indicating they were exploited before any patch was available. Administrators were advised to shut down their NetScaler appliances as a precaution. Citrix has since released a security bulletin detailing these flaws and provided patches on September 27, 2026. The vulnerabilities affect all NetScaler ADC and Gateway deployments, including those with default configurations. Organizations using these systems are urged to apply the updates immediately to mitigate the risk of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (100)
Following this threat?
Track Unc6240, Sideeye and Citrix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…