Skip to content
Critical Zero-Day Vulnerabilities Disclosed in Citrix NetScaler Products

Critical Zero-Day Vulnerabilities Disclosed in Citrix NetScaler Products

First seen 29 Sep 2026, 15:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 16:22 UTC
  • •Two critical zero-day vulnerabilities in Citrix NetScaler products have been disclosed.
  • •CVE-2026-88771 and CVE-2026-88772 allow remote code execution and have a CVSS score of 9.5.
  • •Exploitation of these vulnerabilities has been confirmed in the wild, with attacks reported as early as September 24.

Citrix disclosed critical vulnerabilities affecting its NetScaler ADC and Gateway products, with CVE-2026-88771 and CVE-2026-88772 being particularly severe. Both vulnerabilities have a CVSS score of 9.5, allowing remote code execution and potential denial-of-service attacks. Reports of exploitation began circulating on September 25, prompting Citrix to release patches on September 27. Security experts noted that attacks had likely been occurring for at least a week prior to the disclosure. Users were advised to disable their NetScaler appliances until the vulnerabilities could be mitigated. The vulnerabilities affect default configurations, making many deployments susceptible to attacks. Citrix's advisory emphasized the urgency for customers to update their software immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-25
Reports of exploitation surface
Users noted potential attacks on unpatched NetScaler products, prompting warnings from IT providers.
Darkreading
2026-09-26
Warnings issued by security experts
watchTowr confirmed credible rumors of exploitation and advised immediate action to disable NetScaler appliances.
Darkreading
2026-09-27
Citrix discloses vulnerabilities and releases patches
Citrix published fixes for multiple vulnerabilities, including CVE-2026-88771 and CVE-2026-88772, both rated critical.
support.citrix.com
2026-09-27
CVE-2026-88773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88777 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88774 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88772 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88771 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88776 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88778 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed