Skip to content
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited

Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited

First seen 4 Oct 2026, 08:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 11:02 UTC

In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, with a CVSS score of 9.5. Attackers utilized custom web shells named WHIPSHOT and SLAPSHOT to gain unauthorized access to affected systems. Organizations in sectors such as government, finance, and healthcare were particularly vulnerable. Citrix has since released patches for these vulnerabilities, but the urgency of the situation has raised concerns about the effectiveness of their response. The incidents highlight the ongoing risks associated with internet-exposed edge devices and the need for rapid incident response. As of October 4, 2026, the exploitation is confirmed to be ongoing, with significant operational and compliance risks reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-12-27
CVE-2019-19781 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-10
CVE-2023-4966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19489 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-94127 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CISA adds CVEs to KEV catalog
CVE-2026-88771 and CVE-2026-88772 were added to CISA's Known Exploited Vulnerabilities list, confirming active exploitation.
Shattered
2026-09-27
CVE-2026-88773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88774 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88777 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
CVE-2026-88775 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (9)

Following this threat?

Track Slapshot, Citrix and CVE-2019-19781 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the CVEs involved?
The critical vulnerabilities are CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5.
Who is affected by these vulnerabilities?
Organizations in government, finance, healthcare, and IT sectors are particularly affected.
What should organizations do now?
Organizations must apply the patches released by Citrix immediately to mitigate risks.