Citrix confirms two NetScaler RCE zero-days exploited in attacks
BLUF
Active exploitation of critical Citrix NetScaler zero-days requires immediate patching.
NEWS
Citrix confirmed two remote code execution flaws, CVE-2026-88771 and CVE-2026-88772, are being weaponized in the wild. Security updates are now available to mitigate these critical risks affecting NetScaler ADC and Gateway appliances.
Why I Care
Unpatched systems face immediate compromise risk as attackers leverage these flaws for initial access or lateral movement. This impacts any enterprise relying on Citrix infrastructure for remote access or application delivery.
Next Steps
IT security teams must inventory NetScaler assets and apply the latest security updates immediately. Monitor logs for indicators of compromise related to CVE-2026-88771 and CVE-2026-88772 while patching is deployed.
Source: BleepingComputer ·