Skip to content
Citrix NetScaler Zero-Days Exploited: Urgent Patches Released

Citrix NetScaler Zero-Days Exploited: Urgent Patches Released

First seen 29 Sep 2026, 02:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 02:07 UTC
  • •Citrix confirmed active exploitation of two critical zero-days in NetScaler products.
  • •Patches were released on September 27, 2026, after a significant communication delay.
  • •Over 50,000 Citrix NetScaler instances are potentially vulnerable to these exploits.

Citrix confirmed active exploitation of two critical zero-day vulnerabilities in its NetScaler products, CVE-2026-88771 and CVE-2026-88772, on September 27, 2026. These vulnerabilities, rated 9.5 on the CVSS scale, allow remote code execution and affect all NetScaler appliances in default configurations. The earliest known exploitation attempt occurred on September 24, 2026, when GreyNoise detected a malicious cyber actor attempting to exploit a Citrix NetScaler Gateway. Citrix's delayed communication left customers relying on unofficial channels for threat information. As of September 29, 2026, over 50,000 instances of Citrix NetScaler devices were identified as potentially vulnerable. Citrix has released patches and provided indicators of compromise to assist customers. Attribution for the attacks remains under investigation, with concerns about financially motivated cybercriminals and state-sponsored groups targeting these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
First exploitation attempt detected
GreyNoise observed a malicious actor attempting to exploit a Citrix NetScaler Gateway, although the attempt was unsuccessful.
GreyNoise
2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Citrix disclosed two critical zero-day vulnerabilities, releasing patches for them and six additional defects.
Cyberscoop
2026-09-29
Citrix confirms active exploitation
Citrix acknowledged that attackers were actively exploiting the vulnerabilities, prompting urgent patching.
Cyberscoop

More articles in this cluster (2)

Following this threat?

Track Ryuk, Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed