Skip to content
Critical NetScaler Vulnerabilities Exploited for Remote Code Execution

Critical NetScaler Vulnerabilities Exploited for Remote Code Execution

First seen 2 Oct 2026, 13:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 13:09 UTC
  • •CVE-2026-88771 and CVE-2026-88772 are critical vulnerabilities with a CVSS score of 9.5.
  • •Over 50,000 NetScaler appliances are exposed globally, making them prime targets.
  • •Attackers are using advanced techniques, including PHP web shells and the Platypus C2 framework.

Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a memory overflow bug, was also weaponized in September 2026. Attackers are deploying PHP web shells and a Go-based command-and-control framework named Platypus to maintain persistence and facilitate further intrusions. The vulnerabilities affect critical sectors including government and finance, with over 50,000 exposed instances of NetScaler appliances globally. Patches have been released, but the rapid weaponization indicates a significant risk for organizations that have not yet updated their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-21
Active exploitation confirmed
Exploitation of CVE-2026-88771 was confirmed in the wild, targeting critical sectors.
Forkast.News
2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Both vulnerabilities were disclosed with a CVSS score of 9.5 and added to the CISA KEV catalog.
Forkast.News
2026-09-28
First public PoC for CVE-2026-88771 and CVE-2026-88772
Proof-of-concept code was made publicly available for both vulnerabilities, indicating potential for exploitation.
Forkast.News

More articles in this cluster (2)

Following this threat?

Track Platypus, Education and CVE-2026-19490 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the affected versions of NetScaler?
All versions of Citrix NetScaler ADC and Gateway appliances are affected by these vulnerabilities.
How urgent is the patching process?
Patching is urgent due to active exploitation in the wild; organizations should apply updates immediately.
What should organizations do to mitigate risk?
Organizations should apply the patches provided by Citrix and monitor for any signs of exploitation.