← Back to Feed
Citrix confirms two NetScaler RCE zero-days exploited in attacks
CVE-2026-88771CVE-2026-88772
September 27, 2026 · BleepingComputer · Severity: CRITICAL
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. 📌 **Analyst Note:** This vulnerability is confirmed actively exploited in the wild. Organizations should treat this as an emergency patching priority and monitor for compromise indicators.
Key Takeaways
- US and UK authorities have issued warnings about exploited Citrix NetScaler zero-day bugs, confirming active exploitation of these critical vulnerabilities in ongoing attacks.
- The joint US-UK advisory underscores the severity of these Citrix flaws and the coordinated international effort to alert organizations to active threats.
- Organizations using Citrix NetScaler should apply emergency patches immediately and audit for signs of compromise given confirmed in-the-wild exploitation.