Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On September 27, 2026, Citrix disclosed two zero-day vulnerabilities in NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772. Both flaws are actively exploited, with CVE-2026-88771 allowing unauthenticated command execution and CVE-2026-88772 leading to remote code execution or denial of ser...
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated att...
On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-887...
On September 26, 2026, CISA confirmed the active exploitation of two critical zero-day vulnerabilities in Citrix NetScaler, identified as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities allow remote code execution and affect all default configurations of NetSc...