Skip to content
Citrix NetScaler Vulnerable to Remote Code Execution - CVE-2026-88771

Citrix NetScaler Vulnerable to Remote Code Execution - CVE-2026-88771

First seen 29 Sep 2026, 15:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 20:19 UTC
  • •CVE-2026-88771 is a critical RCE vulnerability in Citrix NetScaler.
  • •Active exploitation is confirmed, with attackers using log injection techniques.
  • •Affected systems include Citrix NetScaler appliances, with no patch available yet.

Citrix NetScaler has been identified as vulnerable to a pre-authentication remote code execution (RCE) issue, CVE-2026-88771, which remains unpatched. The vulnerability was first reported on September 27, 2026, and is actively being exploited. Attackers are using base64 encoded commands in the User Agent to modify server configurations and deploy web shells. The attack method involves log injection, where threat actors fill HTTP logs with malicious payloads, hoping to trigger execution through specific log entries. The European Court of Auditors and the European Central Bank have confirmed the presence of suspicious IP addresses associated with these attacks. As of now, the situation is critical, with active exploitation confirmed. Security professionals are urged to monitor their systems closely and take immediate action.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 published
Citrix disclosed a pre-authentication RCE vulnerability in NetScaler, marking it as critical.
www.cert.europa.eu
2026-09-27
CISA KEV addition
CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog due to active exploitation.
www.cert.europa.eu
2026-09-28
First public PoC released
A proof-of-concept for CVE-2026-88771 was made public, increasing the risk of exploitation.
www.cert.europa.eu
2026-09-29
Active exploitation confirmed
Security analysts confirmed ongoing exploitation attempts against Citrix NetScaler devices.
www.cert.europa.eu

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed