www.cert.europa.eu Citrix NetScaler Vulnerable to Remote Code Execution - CVE-2026-88771
Article Content
- •CVE-2026-88771 is a critical RCE vulnerability in Citrix NetScaler.
- •Active exploitation is confirmed, with attackers using log injection techniques.
- •Affected systems include Citrix NetScaler appliances, with no patch available yet.
Citrix NetScaler has been identified as vulnerable to a pre-authentication remote code execution (RCE) issue, CVE-2026-88771, which remains unpatched. The vulnerability was first reported on September 27, 2026, and is actively being exploited. Attackers are using base64 encoded commands in the User Agent to modify server configurations and deploy web shells. The attack method involves log injection, where threat actors fill HTTP logs with malicious payloads, hoping to trigger execution through specific log entries. The European Court of Auditors and the European Central Bank have confirmed the presence of suspicious IP addresses associated with these attacks. As of now, the situation is critical, with active exploitation confirmed. Security professionals are urged to monitor their systems closely and take immediate action.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…