Labs.Watchtowr Citrix NetScaler Vulnerabilities CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Article Content
- •CVE-2026-88771 and CVE-2026-88772 are actively exploited zero-day vulnerabilities.
- •Both vulnerabilities affect Citrix NetScaler products and require immediate patching.
- •Public proof-of-concepts for both vulnerabilities were released on September 28, 2026.
Citrix has disclosed two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting its NetScaler products. Both vulnerabilities were published on September 27, 2026, and are actively exploited in the wild as zero-days. CVE-2026-88771 involves a pre-authentication command injection, while CVE-2026-88772 is a DTLS pre-auth memory overflow. Both vulnerabilities affect default configurations and are included in Citrix's advisory CTX697096, which recommends updates to specific versions of Citrix NetScaler ADC and Gateway. The vulnerabilities impact numerous organizations relying on Citrix NetScaler for application delivery and remote access. The first public proof-of-concept (PoC) for both vulnerabilities was released on September 28, 2026. Organizations are urged to apply the recommended patches immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…