Rescana Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited
Article Content
- •CVE-2026-88771 and CVE-2026-88772 are critical zero-day vulnerabilities in Citrix products.
- •Active exploitation has been confirmed, affecting government and financial sectors.
- •Citrix released patches, but many systems remain unpatched and at risk.
In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, with a CVSS score of 9.5. Attackers utilized custom web shells named WHIPSHOT and SLAPSHOT to gain unauthorized access to affected systems. Organizations in sectors such as government, finance, and healthcare were particularly vulnerable. Citrix has since released patches for these vulnerabilities, but the urgency of the situation has raised concerns about the effectiveness of their response. The incidents highlight the ongoing risks associated with internet-exposed edge devices and the need for rapid incident response. As of October 4, 2026, the exploitation is confirmed to be ongoing, with significant operational and compliance risks reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Slapshot, Citrix and CVE-2019-19781 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the CVEs involved?
Who is affected by these vulnerabilities?
What should organizations do now?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical NetScaler Vulnerabilities Exploited for Remote Code Execution Threat actors are exploiting two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway appliances, allowing unauthenticated remote code execution. CVE-2026-88771, identified as a pre-authentication RCE flaw, has been since at least September 21, 2026, while CVE-2026-88772, a…