Skip to content
Critical Citrix NetScaler Zero-Day Exploitation Confirmed

Critical Citrix NetScaler Zero-Day Exploitation Confirmed

First seen 28 Sep 2026, 18:18 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 18:20 UTC
  • •Two critical zero-day vulnerabilities in Citrix NetScaler are under active exploitation.
  • •CVE-2026-88771 allows unauthenticated command execution; CVE-2026-88772 can lead to RCE or DoS.
  • •Patches were released on September 27, 2026, with a federal deadline for remediation by September 30.

Citrix has confirmed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in its NetScaler ADC and Gateway products, both scoring 9.5 on the CVSS scale. These vulnerabilities are actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary commands and potentially cause denial-of-service. Citrix released patches on September 27, 2026, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added these vulnerabilities to its Known Exploited Vulnerabilities list. Organizations using affected systems are urged to apply the patches immediately, especially before the September 30 federal remediation deadline. The vulnerabilities impact all deployments with default configurations, making them particularly dangerous for enterprise networks. Citrix has not disclosed the extent of the attacks or the identity of the threat actors involved.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
Citrix releases patches for vulnerabilities
Citrix disclosed eight vulnerabilities, including two critical RCE flaws, and released patches for all affected versions.
Dqindia
2026-09-27
CISA adds vulnerabilities to KEV list
CISA confirmed the active exploitation of CVE-2026-88771 and CVE-2026-88772 and added them to its Known Exploited Vulnerabilities list.
Defendwork
2026-09-27
CVE-2026-88778 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88776 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88777 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88774 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (6)

Following this threat?

Track Citrix and CVE-2026-19490 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed