⌁ DAY 41UNDERCOVERED IN US

Critical Citrix NetScaler zero-day RCE vulnerabilities exploited

Two unpatched remote-code-execution zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) in Citrix NetScaler ADC and Gateway are being actively exploited in attacks as of September 27, 2026. CISA and the Dutch NCSC recommend immediate patching; some IT providers recommend shutting down affected appliances.

15 reports · 14 independentother · primary

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Two unpatched zero-day RCE vulnerabilities in Citrix NetScaler ADC/Gateway are being actively exploited. Dutch NCSC-NL and some IT providers now recommend shutting down appliances https:// deafnews.it

mastodon:infosec-exchangeother2d ago kagi ↗

Two unpatched zero-day RCE vulnerabilities in Citrix NetScaler ADC/Gateway are being actively exploited. Dutch NCSC-NL and some IT providers now recommend shutting down appliances https:// deafnews.it/en/article/two-cit rix-netscaler-zero-day-rces-drive-preemptive-shutdowns

Citrix NetScaler Appliance Users Get Shutdown Orders Over Unpatched Zero-Day Exploits Citrix NetScaler ADC and Gateway appliances are facing active exploitation of two unpatched remote code execution

mastodon:infosec-exchangeother2d ago kagi ↗

Citrix NetScaler Appliance Users Get Shutdown Orders Over Unpatched Zero-Day Exploits Citrix NetScaler ADC and Gateway appliances are facing active exploitation of two unpatched remote code execution vulnerabilities. The Dutch NCSC and security firm watchTowr advised organizations to take systems offline until Citrix releases patches next week. **If you run Citrix NetScaler ADC or Gateway, this is

CVE-2026-88772: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

json:cisa-kevprimary2d ago kagi ↗

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Fore

CVE-2026-88771: Citrix NetScaler — Citrix NetScaler Improper Input Validation Vulnerability

json:cisa-kevprimary2d ago kagi ↗

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see UR

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

rss:cisa-advisoriesprimary2d ago wire ×2 kagi ↗

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771 , CVE-2026-88772 , CVE-2026-88773 , CVE-2026-88774 , CVE-2026-88775 , CVE-2026-88776 , CVE-2026-88777 , and CVE-2026-88778 . CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog . Both are critical,

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0927 ) CISA has added 2 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother35h ago kagi ↗

🚨 [CISA-2026:0927] CISA Adds 2 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0927 ) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. https

mastodon:infosec-exchangeother33h ago kagi ↗

CISA working on a Sunday: Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-887712 were added to the Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. https://www. cisa.gov/news-event/alerts/202 6/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog # KEV # Citrix # NetScaler # zeroday # CVE

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to acti

mastodon:infosec-exchangeother27h ago kagi ↗

⚠️ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler to the Known Exploited Vulnerabilities catalog due to active exploitation in the wild. These are remote code execution vectors being actively weaponized. Federal agencies and any organization running exposed NetScaler instances… https:// threatnoir.com/focus

🤖 Citrix NetScaler ADC/Gateway: CVE-2026-88771 + CVE-2026-88772 (unauth RCE) exploited in the wild. The first hits default configs, the second needs DTLS (enabled by default on VPN vservers). Patches

mastodon:infosec-exchangeother27h ago kagi ↗

🤖 Citrix NetScaler ADC/Gateway: CVE-2026-88771 + CVE-2026-88772 (unauth RCE) exploited in the wild. The first hits default configs, the second needs DTLS (enabled by default on VPN vservers). Patches out, CISA KEV, FCEB deadline Sep 30. Shadowserver: 23k+ exposed IPs. 🔗 https://www. bleepingcomputer.com/news/secu rity/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ # CVE

U.S. # CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199891/hac king/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerab

mastodon:infosec-exchangeother25h ago kagi ↗

U.S. # CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog https:// securityaffairs.com/199891/hac king/u-s-cisa-adds-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html # securityaffairs # hacking

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution.

mastodon:infosec-exchangeother22h ago kagi ↗

CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. https://www. cisa.gov/news-events/alerts/20 26/09/27/cri

⚠️ Threat Notice: Citrix NetScaler ADC and Gateway Vulnerabilities ⚠️ Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway; including two actively exploited. NetScaler ADC

mastodon:infosec-exchangeother20h ago kagi ↗

⚠️ Threat Notice: Citrix NetScaler ADC and Gateway Vulnerabilities ⚠️ Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway; including two actively exploited. NetScaler ADC and NetScaler Gateway sit at the network perimeter, handling VPN, remote access, load balancing, and authentication for enterprise environments, making compromise a high-impact event with broad downs

Recommendations 💡 → Immediate Action: Apply the Citrix-released NetScaler ADC and NetScaler Gateway updates immediately across all affected appliances. → Restrict NetScaler management interface acces

mastodon:infosec-exchangeother20h ago kagi ↗

Recommendations 💡 → Immediate Action: Apply the Citrix-released NetScaler ADC and NetScaler Gateway updates immediately across all affected appliances. → Restrict NetScaler management interface access to trusted internal networks and never expose it to the public internet. → Preserve appliance logs, memory dumps, and configuration snapshots before patching to support forensic review of potential