Techcentral.Ie Citrix NetScaler Zero-Day Vulnerabilities Under
Article Content
- •Critical zero-day vulnerabilities CVE-2026-88771 and CVE-2026-88772 are actively exploited.
- •Attackers are using these flaws to deploy web shells and gain root access.
- •Over 20,000 NetScaler instances are exposed and potentially at risk.
Citrix has issued urgent warnings regarding critical zero-day vulnerabilities in its NetScaler ADC and Gateway products, tracked as CVE-2026-88771 and CVE-2026-88772. These vulnerabilities, which involve remote code execution and memory overflow, are being actively exploited, with attackers reportedly using them to deploy web shells and gain unauthorized access to networks. The US Cybersecurity and Infrastructure Security Agency (CISA) added both CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, indicating. Citrix's security bulletin highlights that over 20,000 instances are exposed and potentially at risk. Security experts have confirmed that the vulnerabilities have been exploited in the wild since at least early September, affecting sectors including government, finance, and education. Citrix has advised organizations to upgrade their systems immediately to mitigate risks. The urgency of the situation is underscored by reports of compromises, although widespread impacts have not yet been confirmed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…