Forkast.News Critical NetScaler Vulnerabilities Exploited for Remote Code Execution
Article Content
- •CVE-2026-88771 and CVE-2026-88772 are critical vulnerabilities with a CVSS score of 9.5.
- •Over 50,000 NetScaler appliances are exposed globally, making them prime targets.
- •Attackers are using advanced techniques, including PHP web shells and the Platypus C2 framework.
Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a memory overflow bug, was also weaponized in September 2026. Attackers are deploying PHP web shells and a Go-based command-and-control framework named Platypus to maintain persistence and facilitate further intrusions. The vulnerabilities affect critical sectors including government and finance, with over 50,000 exposed instances of NetScaler appliances globally. Patches have been released, but the rapid weaponization indicates a significant risk for organizations that have not yet updated their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Platypus, Education and CVE-2026-19490 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the affected versions of NetScaler?
How urgent is the patching process?
What should organizations do to mitigate risk?
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…