Skip to content
Citrix NetScaler Zero-Day Vulnerabilities Under

Citrix NetScaler Zero-Day Vulnerabilities Under

First seen 30 Sep 2026, 09:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 09:36 UTC
  • •Critical zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772 are actively exploited.
  • •Attackers are using these flaws to deploy web shells and gain root access.
  • •Over 20,000 NetScaler instances are exposed and potentially at risk.

Citrix has issued urgent warnings regarding critical zero-day vulnerabilities in its NetScaler ADC and Gateway products, tracked as CVE-2026-88771 and CVE-2026-88772. These vulnerabilities, which involve remote code execution and memory overflow, are being actively exploited, with attackers reportedly using them to deploy web shells and gain unauthorized access to networks. The US Cybersecurity and Infrastructure Security Agency (CISA) added both CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, indicating. Citrix's security bulletin highlights that over 20,000 instances are exposed and potentially at risk. Security experts have confirmed that the vulnerabilities have been exploited in the wild since at least early September, affecting sectors including government, finance, and education. Citrix has advised organizations to upgrade their systems immediately to mitigate risks. The urgency of the situation is underscored by reports of compromises, although widespread impacts have not yet been confirmed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-27
CVE-2026-88771 and CVE-2026-88772 added to CISA KEV
CISA confirmed active exploitation of the vulnerabilities and added them to its Known Exploited Vulnerabilities catalog.
Techcentral.Ie
2026-09-28
First public PoC for CVE-2026-88771 and CVE-2026-88772
Proof-of-concept code for the vulnerabilities was made publicly available, increasing the urgency for patching.
Techcentral.Ie
2026-09-29
Escalation of exploitation tactics reported
Attackers began using the vulnerabilities to plant web shells and gain root access within targeted networks.
Feeds.4Sysops

More articles in this cluster (6)

Following this threat?

Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed