Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings
Citrix said the flaws let attackers run commands without logging in or trigger remote code execution, and both score 9.5 out of 10 for severity.
- The Cybersecurity and Infrastructure Security Agency added two critical Citrix NetScaler vulnerabilities to its known exploited list on Sunday after Citrix confirmed active attacks and released security patches.
- Attackers are actively exploiting CVE-2026-88771 and CVE-2026-88772, critical flaws affecting all NetScaler ADC and Gateway deployments that allow remote code execution and command injection on unmitigated devices.
- Palo Alto Networks identified more than 50,000 potentially vulnerable NetScaler instances as of Sunday, while both flaws score 9.5 out of 10 for severity, prompting CISA to mandate federal agency remediation.
- Ben Harris, CEO at watchTowr, called Citrix's delayed disclosure 'unconscionably irresponsible' in a LinkedIn post, as security professionals criticized the vendor for remaining silent for more than 36 hours during active exploitation.
- Security researcher Kevin Beaumont wrote that attackers are 'probably nation state aligned,' while CISA warned organizations to check for compromise before patching, as updates can erase critical forensic evidence.
14 Articles
14 Articles
A vulnerability in the security software Citrix has once again caused problems for government organizations and hospitals. Following a warning from the National Cyber Security Center (NCSC), various institutions have shut down their systems as a precaution. According to tech expert Bert Hubert, warnings about an impending leak have been issued for weeks, but Citrix took no action. "You hope that this is the straw that breaks the camel's back."
Hackers exploit two critical Citrix NetScaler zero-days
Attackers are exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway. Companies use the devices to give staff remote access to internal networks. Citrix confirmed the attacks in a security bulletin on Sunday and released fixes. Both flaws were exploited before a patch existed. “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments […] This story continues at The Next Web
The problems facing the company Citrix last weekend were exploited at least twice, the National Cyber Security Centre (NCSC) confirms. The central government and various hospitals, among others, use Citrix's digital systems. The ‘vulnerabilities’ in the system could, for example, make it possible to gain remote access to the system.
At several hospitals, patients were unable to access their data last weekend, and civil servants working from home are experiencing difficulties logging in. In 2025, hackers gained access to the Public Prosecution Service's virtual work environment via a vulnerability in Citrix.
Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
The US Cybersecurity and Infrastructure Security Agency has warned that critical zero-day vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway are facing exploitation and need to be immediately addressed. Citrix said the exploitation is linked to a remote code execution (RCE) vulnerability due to improper input validation, tracked as CVE-2026-88771, and a memory overflow […]
Coverage Details
Bias Distribution
- 40% of the sources lean Left, 40% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium









