Two unpatched remote-code-execution zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) in Citrix NetScaler ADC and Gateway are being actively exploited in attacks as of September 27, 2026. CISA and the Dutch NCSC recommend immediate patching; some IT providers recommend shutting down affected appliances.
15 reports · 14 independentother · primary
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Two unpatched zero-day RCE vulnerabilities in Citrix NetScaler ADC/Gateway are being actively exploited. Dutch NCSC-NL and some IT providers now recommend shutting down appliances https:// deafnews.it/en/article/two-cit rix-netscaler-zero-day-rces-drive-preemptive-shutdowns
Citrix NetScaler Appliance Users Get Shutdown Orders Over Unpatched Zero-Day Exploits Citrix NetScaler ADC and Gateway appliances are facing active exploitation of two unpatched remote code execution vulnerabilities. The Dutch NCSC and security firm watchTowr advised organizations to take systems offline until Citrix releases patches next week. **If you run Citrix NetScaler ADC or Gateway, this is
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Fore
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see UR
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771 , CVE-2026-88772 , CVE-2026-88773 , CVE-2026-88774 , CVE-2026-88775 , CVE-2026-88776 , CVE-2026-88777 , and CVE-2026-88778 . CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog . Both are critical,
🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0927 ) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder
CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. https://www. cisa.gov/news-event/alerts/202 6/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog # KEV # Citrix # NetScaler # zeroday # CVE
⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances… https:// threatnoir.com/focus
U.S. # CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199891/hac king/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html # securityaffairs # hacking
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. https://www. cisa.gov/news-events/alerts/20 26/09/27/cri
⚠️ Threat Notice: Citrix NetScaler ADC and Gateway Vulnerabilities ⚠️ Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway; including two actively exploited. NetScaler ADC and NetScaler Gateway sit at the network perimeter, handling VPN, remote access, load balancing, and authentication for enterprise environments, making compromise a high-impact event with broad downs
Recommendations 💡 → Immediate Action: Apply the Citrix-released NetScaler ADC and NetScaler Gateway updates immediately across all affected appliances. → Restrict NetScaler management interface access to trusted internal networks and never expose it to the public internet. → Preserve appliance logs, memory dumps, and configuration snapshots before patching to support forensic review of potential