search
CVE-2026-88772
Trends
- 1Citrix NetScaler flaws actively exploited, thousands exposed●🤖 Citrix NetScaler ADC/Gateway: CVE-2026-88771 + CVE-2026-88772 (unauth RCE) exploited in the wild. The first hits defau
Two unauthenticated remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in the wild against Citrix NetScaler ADC and Gateway appliances. The first affects default configurations, while the second requires DTLS, which is enabled by default on VPN virtual servers. Patches are available, the flaws have been added to CISA's Known Exploited Vulnerabilities catalog with a federal patching deadline of September 30, and Shadowserver reports over 23,000 exposed instances online.
- 2CISA adds two actively exploited Citrix NetScaler flaws to catalog▼⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affec
CISA has added CVE-2026-88771 and CVE-2026-88772, two vulnerabilities affecting Citrix NetScaler, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Both flaws are described as remote code execution vectors, meaning attackers can potentially run malicious code on affected appliances. Security teams are urged to check whether they run NetScaler and apply patches immediately, as exploited edge devices are a common entry point for intrusions.
- 3Citrix confirms two actively exploited NetScaler zero-day flaws●Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-8877
Citrix has confirmed two zero-day remote code execution vulnerabilities in its NetScaler application delivery products, tracked as CVE-2026-88771 and CVE-2026-88772, both under active exploitation. The company has released patches, and security researchers are urging administrators to update internet-facing NetScaler and VPN appliances immediately, warning that unpatched systems could allow attackers to run code remotely.
- 4Citrix patches two actively exploited NetScaler zero-days●🚨 CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37
Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.