Citrix confirms two NetScaler RCE zero-days exploited in attacks

Refract AI Intelligence Digest

BLUF

Active exploitation of critical Citrix NetScaler zero-days requires immediate patching.

NEWS

Citrix confirmed two remote code execution flaws, CVE-2026-88771 and CVE-2026-88772, are being weaponized in the wild. Security updates are now available to mitigate these critical risks affecting NetScaler ADC and Gateway appliances.

Why I Care

Unpatched systems face immediate compromise risk as attackers leverage these flaws for initial access or lateral movement. This impacts any enterprise relying on Citrix infrastructure for remote access or application delivery.

Next Steps

IT security teams must inventory NetScaler assets and apply the latest security updates immediately. Monitor logs for indicators of compromise related to CVE-2026-88771 and CVE-2026-88772 while patching is deployed.

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.