Skip to content
Critical Zero-Day Exploits Target Citrix and Other Major Platforms

Critical Zero-Day Exploits Target Citrix and Other Major Platforms

First seen 29 Sep 2026, 01:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 01:10 UTC
  • •Multiple critical zero-day vulnerabilities are actively exploited, including CVE-2026-88771 and CVE-2026-88772.
  • •CISA has listed CVE-2026-83548 and CVE-2026-83549 as actively exploited vulnerabilities.
  • •Organizations must prioritize patching to prevent unauthorized remote code execution.

Recent reports indicate multiple critical vulnerabilities are being actively exploited, including zero-day exploits for Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772) and PaperCut NG/MF. The vulnerabilities allow unauthenticated remote code execution, posing significant risks to affected systems. Additionally, critical vulnerabilities in F5 BIG-IP APM, Cisco Secure Email Gateway, and GitLab have also been exploited in the wild. CVE-2026-83548 and CVE-2026-83549, affecting SonicWall SMA1000, were added to the CISA KEV catalog on September 2, 2026, with active exploitation confirmed. The urgency for organizations to patch these vulnerabilities is high, as proof-of-concept code for CVE-2026-88771 was made public on September 28, 2026. Security teams are advised to prioritize remediation efforts to mitigate potential impacts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2020-03-02
CVE-2020-6764 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-22
CVE-2025-57977 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-22
CVE-2025-58002 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-22
CVE-2025-57989 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-22
CVE-2025-57981 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-63520 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83548 and CVE-2026-83549 published
SonicWall SMA1000 vulnerabilities disclosed, with active exploitation confirmed shortly after.
Rapid7
2026-09-02
CVE-2026-83548 and CVE-2026-83549 added to CISA KEV
CISA confirmed active exploitation of these vulnerabilities in the wild.
Rapid7
2026-09-27
CVE-2026-88771 published
Critical vulnerability in Citrix NetScaler ADC and Gateway disclosed, with exploitation confirmed.
Rapid7
2026-09-28
First public PoC for CVE-2026-88771
Proof-of-concept code for the Citrix vulnerability was released, increasing the urgency for patching.
Rapid7

More articles in this cluster (2)

Following this threat?

Track CVE-2015-1583 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed