โ† Back to Feed

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

CVE-2026-88771CVE-2026-88772

September 28, 2026 ยท Unit 42 ยท Severity: CRITICAL

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42. ๐Ÿ“Œ **Analyst Note:** This vulnerability is confirmed actively exploited in the wild. Organizations should treat this as an emergency patching priority and monitor for compromise indicators.

Key Takeaways

  • A threat brief details NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which are being actively exploited to compromise Citrix application delivery controllers.
  • The critical NetScaler vulnerabilities allow unauthenticated remote code execution, making them a top priority for organizations using Citrix infrastructure.
  • Organizations using Citrix NetScaler should apply emergency patches immediately and audit for signs of compromise.
โ˜• Buy a Coffee