Skip to content
Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA

Critical Zero-Day Exploits in Citrix NetScaler Confirmed by CISA

First seen 29 Sep 2026, 13:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 13:11 UTC
  • •CISA confirmed active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler.
  • •Vulnerabilities CVE-2026-88771 and CVE-2026-88772 allow remote code execution with a CVSS score of 9.5.
  • •Administrators were urged to disconnect systems before official patch release, indicating ongoing attacks.

On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetScaler ADC and Gateway. Reports indicated that administrators were advised to disconnect their systems without prior explanation, signaling ongoing exploitation. Citrix released security updates on September 27, 2026, but the vulnerabilities had already been exploited before patches were available. The vulnerabilities stem from improper input validation and a buffer overflow, impacting numerous organizations worldwide. The National Cybersecurity Centre of the Netherlands alerted local organizations based on information from a European CERT. The situation underscores the urgency for affected organizations to apply the patches immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19489 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-26
CISA adds CVEs to KEV list
CISA confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772, prompting immediate alerts.
Ciberseguridadlatam
2026-09-27
Citrix releases security updates
Citrix issued patches for the vulnerabilities after confirming they were being exploited in the wild.
Acn.It
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-28
Public PoC released
Proof-of-concept code for the vulnerabilities was made publicly available, increasing risk of exploitation.
Acn.It

More articles in this cluster (2)

Following this threat?

Track Citrix and CVE-2026-19489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed