Critical Zero-Day Vulnerabilities in Citrix NetScaler Disclosed
Article Content
- •Two critical vulnerabilities in Citrix NetScaler (CVE-2026-88771, CVE-2026-88772) are actively exploited.
- •CISA added these vulnerabilities to its KEV catalog on September 27, 2026.
- •Organizations are urged to apply patches immediately to mitigate risks.
On September 27, 2026, two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were published affecting Citrix NetScaler ADC and Gateway products. These vulnerabilities are currently under active exploitation, as confirmed by CISA, which added them to its Known Exploited Vulnerabilities (KEV) catalog on the same day. The vulnerabilities allow attackers to execute arbitrary code, potentially compromising sensitive data and systems. Organizations using affected versions of Citrix NetScaler are at risk, with urgent recommendations to apply patches or mitigate exposure. The vulnerabilities are linked to automated or suspicious activity patterns that may indicate exploitation attempts. Citrix has not yet released specific details on the affected versions but has acknowledged the severity of the situation. Security teams are advised to monitor their systems closely for any signs of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…