Kyberturvallisuuskeskus.Fi Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required
Article Content
- •CVE-2026-88771 and CVE-2026-88772 are critical vulnerabilities with a CVSS score of 9.5.
- •CISA mandated federal agencies to patch these vulnerabilities by September 30, 2026.
- •Active exploitation has been confirmed since September 3, 2026, by a suspected state-backed group.
Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated federal agencies to patch by September 30. Reports indicate that these vulnerabilities have been actively exploited since September 3, 2026, by a suspected state-backed group using custom web shells. Organizations in sectors such as banking, healthcare, and government are urged to update their systems immediately and conduct forensic checks for prior exploitation. The situation is critical, as failure to patch could lead to significant control over affected devices. The vulnerabilities allow for remote code execution and other severe impacts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Slapshot and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the CVEs associated with this vulnerability?
How urgent is the patching process?
What should organizations do to protect themselves?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…