Skip to content
Critical Zero-Day Vulnerabilities Exploited in Citrix and Kiteworks Systems

Critical Zero-Day Vulnerabilities Exploited in Citrix and Kiteworks Systems

First seen 4 Oct 2026, 08:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 09:03 UTC
  • •Two critical zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) are actively exploited.
  • •Citrix and Kiteworks faced significant operational risks, prompting emergency patches and shutdown advisories.
  • •Regulatory bodies confirmed exploitation, emphasizing the need for rapid detection and coordinated responses.

In late September 2026, critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) were actively exploited in Citrix NetScaler ADC and Gateway, as well as Kiteworks appliances. These vulnerabilities allowed attackers to execute remote code, escalating privileges and exfiltrating sensitive data across sectors including government and finance. Citrix confirmed that these vulnerabilities were being actively exploited, prompting emergency patches. Kiteworks took the unusual step of advising customers to shut down systems for nine hours to mitigate risks, despite only 1% of their customer base being affected. Regulatory bodies, including CISA, issued urgent advisories, highlighting the need for improved vulnerability management and incident response coordination. The incidents underscore the ongoing challenges organizations face in defending against zero-day threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-12-27
CVE-2019-19781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-10
CVE-2023-4966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19489 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
Initial detection of attacks
GreyNoise Intelligence observed a US-based IP scanning for Citrix NetScaler installations and conducting RCE attacks.
Darkreading
2026-09-25
Kiteworks advises shutdown
Kiteworks recommended customers take their systems offline for nine hours due to imminent attack intelligence.
Darkreading
2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Both vulnerabilities were published and added to CISA KEV due to active exploitation.
B2B-Cyber-Security.De
2026-10-02
Emergency patches released
Citrix released patches for eight vulnerabilities, including CVE-2026-88771 and CVE-2026-88772.
aviatrix.ai

More articles in this cluster (7)

Following this threat?

Track Slapshot, Citrix and CVE-2019-19781 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected?
Citrix NetScaler ADC, Citrix NetScaler Gateway, and Kiteworks appliances are affected.
What should organizations do now?
Organizations should apply the emergency patches released by Citrix and Kiteworks immediately.
How serious is the threat?
The vulnerabilities are critical with active exploitation confirmed, posing significant risks to affected sectors.