Ciberseguridadlatam Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA
Article Content
- •CISA confirmed active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler.
- •Vulnerabilities CVE-2026-88771 and CVE-2026-88772 allow remote code execution with a CVSS score of 9.5.
- •Administrators were urged to disconnect systems before official patch release, indicating ongoing attacks.
On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and Gateway. Reports indicated that administrators were advised to disconnect their systems without prior explanation, signaling ongoing exploitation. Citrix released security updates on September 27, 2026, but the vulnerabilities had already been exploited before patches were available. The vulnerabilities stem from improper input validation and a buffer overflow, impacting numerous organizations worldwide. The National Cybersecurity Centre of the Netherlands alerted local organizations based on information from a European CERT. The situation underscores the urgency for affected organizations to apply the patches immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrix and CVE-2026-19489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…