Citrix patches two NetScaler zero-days exploited in attacks
Citrix confirmed on Sept. 27 that attackers were exploiting two previously undisclosed remote-code-execution flaws in NetScaler ADC and Gateway and released security updates.
Citrix confirmed on Sept. 27 that attackers were exploiting two previously undisclosed remote-code-execution flaws in NetScaler ADC and Gateway and released security updates.
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Citrix confirmed on Sept. 27 that attackers were exploiting two previously undisclosed remote-code-execution flaws in NetScaler ADC and Gateway and released security updates. CVE-2026-88771, rated 9.5, allows an unauthenticated attacker to execute commands and affects all deployments running vulnerable versions. CVE-2026-88772, also rated 9.5, is a memory-overflow flaw that can enable remote code
‼️ WARNING — Citrix NetScaler is facing two unpatched RCE 0-days under active exploitation. Researchers at watchTowr say the flaws are being exploited in the wild. Citrix has not confirmed them or released a patch, affected-version guidance, workaround, or indicators of compromise. What defenders should know now: https:// thehackernews.com/2026/09/warn ing-two-unpatched-citrix-netscaler.html
🤖 Two unpatched Citrix NetScaler ADC/Gateway RCE zero-days are being exploited in the wild, per watchTowr (26 Sept). No advisory, no fix, no IOCs; patch expected week of 28 Sept. Distinct from CVE-2026-19490 (fixed 19 Aug). Some admins are taking appliances offline. 🔗 https:// thehackernews.com/2026/09/warn ing-two-unpatched-citrix-netscaler.html # Citrix # NetScaler # 0day # CyberSec
Hacker News: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation https:// thehackernews.com/2026/09/warn ing-two-unpatched-citrix-netscaler.html # news # IT
🔹 The Hacker News Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some administrators say t
Citrix NetScaler ADC/Gatewayで、リモートコード実行を可能にする2件の未修正ゼロデイ脆弱性が発見され、活発に悪用されている。Citrixは修正を公表していない。 watchTowr says two unpatched NetScaler RCE flaws were exploited before fixes, while Citrix has yet to publish a bulletin or patch.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are frequent attack vectors for malicious c
watchTowr reports two unpatched remote-code-execution flaws in Citrix NetScaler ADC and Gateway are being exploited in the wild. No patch, advisory, or IOCs have been published yet ahead of expected vendor communication. Internet-facing instances must be assumed at risk and prioritized for monitoring and forensic review. # CitrixNetScaler # ZeroDay # RemoteCodeExecution https:// cyberworldops.eu/e
Two unpatched RCE flaws in Citrix NetScaler ADC and Gateway are being exploited in the wild, per watchTowr, which found them during forensic work on compromised appliances. Citrix has no patch yet, expected the week of Sept 28. thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html watchTowr found the flaws exploited before any fix existed; Citrix patches expected the week of Sept 2
Third NetScaler emergency since June. watchTowr says two unpatched remote code execution flaws in NetScaler ADC and Gateway are being exploited, found during forensic work. No Citrix bulletin, no CVEs, no fix, with patches expected early next week. Some admins are not waiting: appliances are going offline, reportedly on a Dutch national CERT pre-notification. The decision set this weekend is not p
Two Citrix NetScaler zero-day flaws enabling remote code execution are reportedly under active exploitation. No CVE or patch yet. See mitigation steps. # Citrix # NetScaler # ZeroDay # RCE # CyberSecurity # VPN # watchTowr # PatchNow https:// securityonline.info/citrix-net scaler-zero-day-rce/?utm_source=mastodon&utm_medium=jetpack_social
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. https://www. bleepingcomputer.com/news/secu rity/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
We have updated our coverage of the new # Citrix # Netscaler vulnerabilities with the vendor's advisory. https:// ifin.network/t/multiple-citrix -netscaler-0-days-exploited/867 # IFIN # ThreatIntel # ThreatIntelligence
Two Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-88772 and shipped patches. Update now. # Citrix # NetScaler # ZeroDay # RCE # CyberSecurity # VPN # watchTowr # PatchNow https:// securityonline.info/citrix-net scaler-zero-day-rce/?utm_source=mastodon&utm_medium=jetpack_social
🤖 Citrix NetScaler ADC/Gateway: two RCE zero-days exploited in the wild before any fix, CVSS v4 9.5 each. CVE-2026-88771 hit every deployment (unauth command execution); CVE-2026-88772 needs DTLS, on by default for VPN vservers. Fixed in 14.1-73.37 / 13.1-64.23. 🔗 https:// thehackernews.com/2026/09/warn ing-two-unpatched-citrix-netscaler.html # CVE # Exploit # NetScaler # CyberSec
# Citrix Confirmed Two New # NetScaler Flaws Exploited as Zero-Day https:// securityaffairs.com/199873/sec urity/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html # securityaffairs # hacking
Critical Vulnerabilities in Citrix NetScaler ADC and Gateway (CERT-EU Security Advisory 2026-014) On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2
https:// undercodenews.com/citrix-netsc aler-zero-day-crisis-official-patches-released-for-two-exploited-critical-rce-vulnerabilities-video/?utm_source=mastodon&utm_medium=jetpack_social # ZeroDay # Citrix # NetScaler # RCE # CyberSecurity # PatchedOrPerish (3/3)
https:// securityaffairs.com/199873/sec urity/citrix-confirmed-two-new-netscaler-flaws-exploited-as-zero-day.html # Citrix # NetScaler # ZeroDay # RemoteCodeExecution # CyberSecurity # PatchedOrPerish (3/3)
Both affect Citrix NetScaler ADC and NetScaler Gateway. Both are being actively exploited on unpatched deployments in the wild right now. This is not a cutscene. You cannot pause. Install the Citrix NetScaler ADC and NetScaler Gateway updates immediately to clear these debuffs before the next enemy wave does it for you. Reward: You've unlocked the Cursed Loadout — two critical zero-days equipped s
Citrix NetScaler zero-days exploited before patches arrive Admins urged to disable appliances as attacks target unpatched flaws https:// hostingpaper.com/article/citri x-netscaler-zero-days-exploited-before-patches-arrive # Security # Vulnerabilities
Citrix NetScaler zero-day reportedly exploited in the wild, with no patch or official guidance available yet. Some admins are pulling external access to their NetScalers entirely until Citrix confirms a fix. View post on Reddit.
Citrix confirmed on Sept. 27 that attackers are exploiting two critical, previously undisclosed remote-code-execution flaws in NetScaler ADC and Gateway appliances and released security updates. CVE-2026-88771 affects all deployments running affected versions; CVE-2026-88772 affects systems with DTLS enabled. DTLS is enabled by default for VPN virtual servers. Both flaws can allow unauthenticated
Active Citrix zero-days delivering remote code execution to strangers again. The network perimeter exists primarily to ensure sysadmins never experience uninterrupted weekends. https://www. cisa.gov/news-events/alerts/20 26/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
If you're looking at a Citrix NetScaler ADC or Gateway this morning, you probably saw the warning; two zero-days are being used in the wild right now. https:// theperimetersite.com/report/310 # vulnerability # infosec
⚠️ CRITICAL: Citrix confirms two NetScaler RCE zero-days exploited in attacks Citrix NetScaler ADC and Gateway appliances are under active attack via two unpatched RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Unauthenticated attackers can execute arbitrary commands or trigger denial-of-service on vulnerable instances. Any organization running these appliances without t… https:// threatnoir.c
⚠️ CRITICAL: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Two unpatched zero-day RCE vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation. No CVEs or patches are available yet. Any organization running these appliances is at immediate risk of compromise. https:// threatnoir.com/focus # infosec # cybersecurity 🤖 AI generate
Tenable, posted yesterday: Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities https://www. tenable.com/blog/frequently-as ked-questions-about-reported-citrix-netscaler-zero-day-vulnerabilities @ tenable # infosec # vulnerability # Citrix # NetScaler @ ifin
https:// youtu.be/OE4aF4FWJqs Two exploited enterprise vulnerabilities require urgent attention today: Citrix NetScaler ADC/Gateway zero-days and renewed Oracle PeopleSoft exploitation linked to ShinyHunters reporting. # Cybersecurity # UrgentPatching # VulnerabilityManagement
🚨RAPID RESPONSE: Two critical Citrix NetScaler vulnerabilities are being actively exploited as zero-days. CVE-2026-88771 and CVE-2026-88772 can each lead to remote code execution. Censys currently observes 42,735 Internet-exposed NetScaler ADC or Gateway hosts. Censys ARC breaks down the exposed population, exploitation status, patches, and guidance for defenders. Read the advisory: https:// cens
🔵 THREAT INTELLIGENCE Citrix confirms two NetScaler RCE zero-days exploited in attacks Vulnerability | CRITICAL CVEs: CVE-2026-88771, CVE-2026-88772 Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being... Full analysis: https://www. yazoul.net/news/article/citrix -confirms-two-netscaler-rce-zero-days-exploi
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-29 CISA confirms active exploitation of two critical Citrix NetScaler ADC/Gateway flaws—patch immediately, these are prime targets for initial access. https:// thehackernews.com/2026/09/cisa -says-attackers-are-exploiting-two.html # CVE # Citrix # InfoSec # Cybersecurity