Skip to content
ThreatCluster

Critical Zero-Day Vulnerabilities in Citrix NetScaler Disclosed

First seen 28 Sep 2026, 10:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 11:04 UTC
  • •Two critical vulnerabilities in Citrix NetScaler (CVE-2026-88771, CVE-2026-88772) are actively exploited.
  • •CISA added these vulnerabilities to its KEV catalog on September 27, 2026.
  • •Organizations are urged to apply patches immediately to mitigate risks.

On September 27, 2026, two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were published affecting Citrix NetScaler ADC and Gateway products. These vulnerabilities are currently under active exploitation, as confirmed by CISA, which added them to its Known Exploited Vulnerabilities (KEV) catalog on the same day. The vulnerabilities allow attackers to execute arbitrary code, potentially compromising sensitive data and systems. Organizations using affected versions of Citrix NetScaler are at risk, with urgent recommendations to apply patches or mitigate exposure. The vulnerabilities are linked to automated or suspicious activity patterns that may indicate exploitation attempts. Citrix has not yet released specific details on the affected versions but has acknowledged the severity of the situation. Security teams are advised to monitor their systems closely for any signs of exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Citrix disclosed two critical vulnerabilities affecting NetScaler ADC and Gateway products, enabling arbitrary code execution.
Socradar
2026-09-27
CISA adds CVEs to KEV catalog
CISA confirmed active exploitation of the vulnerabilities and included them in its Known Exploited Vulnerabilities catalog.
Cyber.Au

More articles in this cluster (2)

Following this threat?

Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed