Skip to content
Citrix NetScaler Vulnerabilities Under Active Exploitation

Citrix NetScaler Vulnerabilities Under Active Exploitation

First seen 28 Sep 2026, 21:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 21:09 UTC
  • •Two critical vulnerabilities in Citrix NetScaler are actively exploited.
  • •CVE-2026-88771 allows remote command execution; CVE-2026-88772 can lead to remote code execution.
  • •Over 20,000 instances of NetScaler are potentially exposed to these vulnerabilities.

On September 27, 2026, Citrix disclosed eight vulnerabilities in its NetScaler ADC and Gateway, including two critical flaws, CVE-2026-88771 and CVE-2026-88772, which are actively exploited. CVE-2026-88771, an improper input validation vulnerability, allows remote unauthenticated attackers to execute arbitrary commands. CVE-2026-88772, a memory overflow vulnerability, can lead to remote code execution or denial of service. Both vulnerabilities received a CVSS v4 score of 9.5 and were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day. Security teams were urged to disconnect affected servers immediately due to the ongoing exploitation, with reports indicating over 20,000 instances potentially at risk. Citrix has released indicators of compromise (IOCs) to assist in identifying compromised systems. The urgency of the situation has led to widespread alerts from security firms and government agencies.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
Citrix discloses vulnerabilities
Citrix announced eight vulnerabilities in NetScaler ADC and Gateway, including two critical flaws under active exploitation.
Fieldeffect
2026-09-27
CISA adds CVEs to KEV catalog
CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog after reports of active exploitation.
Cybersecuritydive
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
Public PoC released
The first public proof-of-concept for CVE-2026-88771 and CVE-2026-88772 was released, increasing the risk of exploitation.
Fieldeffect

More articles in this cluster (2)

Following this threat?

Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed