Skip to content
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required

Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required

First seen 1 Oct 2026, 22:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 22:11 UTC
  • •CVE-2026-88771 and CVE-2026-88772 are critical vulnerabilities with a CVSS score of 9.5.
  • •CISA mandated federal agencies to patch these vulnerabilities by September 30, 2026.
  • •Active exploitation has been confirmed since September 3, 2026, by a suspected state-backed group.

Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated federal agencies to patch by September 30. Reports indicate that these vulnerabilities have been actively exploited since September 3, 2026, by a suspected state-backed group using custom web shells. Organizations in sectors such as banking, healthcare, and government are urged to update their systems immediately and conduct forensic checks for prior exploitation. The situation is critical, as failure to patch could lead to significant control over affected devices. The vulnerabilities allow for remote code execution and other severe impacts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-94127 added to CISA KEV
CVE-2026-94127 was added to the CISA KEV catalog due to active exploitation, with a CVSS score of 9.8.
Shattered
2026-09-27
CVE-2026-88771 and CVE-2026-88772 added to CISA KEV
CISA added CVE-2026-88771 and CVE-2026-88772 to its KEV catalog, confirming active exploitation.
Shattered
2026-09-27
CVE-2026-88775 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88774 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88776 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88777 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-30
Federal patch deadline
CISA set a deadline for federal agencies to patch the vulnerabilities or take affected systems offline.
Shattered

More articles in this cluster (2)

Following this threat?

Track Slapshot and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the CVEs associated with this vulnerability?
The critical vulnerabilities are CVE-2026-88771 and CVE-2026-88772.
How urgent is the patching process?
Patching is urgent as CISA mandated federal agencies to complete it by September 30, 2026.
What should organizations do to protect themselves?
Organizations must update their Citrix NetScaler products immediately and check for signs of exploitation.