Citrix NetScaler Vulnerabilities Under Active Exploitation
Article Content
- •Two critical vulnerabilities in Citrix NetScaler are actively exploited.
- •CVE-2026-88771 allows remote command execution; CVE-2026-88772 can lead to remote code execution.
- •Over 20,000 instances of NetScaler are potentially exposed to these vulnerabilities.
On September 27, 2026, Citrix disclosed eight vulnerabilities in its NetScaler ADC and Gateway, including two critical flaws, CVE-2026-88771 and CVE-2026-88772, which are actively exploited. CVE-2026-88771, an improper input validation vulnerability, allows remote unauthenticated attackers to execute arbitrary commands. CVE-2026-88772, a memory overflow vulnerability, can lead to remote code execution or denial of service. Both vulnerabilities received a CVSS v4 score of 9.5 and were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the same day. Security teams were urged to disconnect affected servers immediately due to the ongoing exploitation, with reports indicating over 20,000 instances potentially at risk. Citrix has released indicators of compromise (IOCs) to assist in identifying compromised systems. The urgency of the situation has led to widespread alerts from security firms and government agencies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Days Exploited: Urgent Patching Required Citrix has confirmed active exploitation of two critical zero-day vulnerabilities in its NetScaler ADC and Gateway products, identified as CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale. These vulnerabilities allow unauthenticated attackers to execute arbitrary commands and potentially cause…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…