Kyberturvallisuuskeskus.Fi Critical Zero-Day Vulnerabilities Exploited in Citrix and Kiteworks Systems
Article Content
- •Two critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) are actively exploited.
- •Citrix and Kiteworks faced significant operational risks, prompting emergency patches and shutdown advisories.
- •Regulatory bodies confirmed exploitation, emphasizing the need for rapid detection and coordinated responses.
In late September 2026, critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) were actively exploited in Citrix NetScaler ADC and Gateway, as well as Kiteworks appliances. These vulnerabilities allowed attackers to execute remote code, escalating privileges and exfiltrating sensitive data across sectors including government and finance. Citrix confirmed that these vulnerabilities were being actively exploited, prompting emergency patches. Kiteworks took the unusual step of advising customers to shut down systems for nine hours to mitigate risks, despite only 1% of their customer base being affected. Regulatory bodies, including CISA, issued urgent advisories, highlighting the need for improved vulnerability management and incident response coordination. The incidents underscore the ongoing challenges organizations face in defending against zero-day threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Slapshot, Citrix and CVE-2019-19781 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which systems are affected?
What should organizations do now?
How serious is the threat?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical NetScaler Vulnerabilities Exploited for Remote Code Execution Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a…