< Back to all clusters
[TECHNOLOGY] · United States, Canada, Japan · 5 sources

started · updated

Citrix NetScaler zero-days face active global exploitation

Cloud Software Group has disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and NetScaler Gateway products. Both flaws carry a CVSS score of 9.5. CVE-2026-88771 allows unauthenticated command execution, while CVE-2026-88772 enables remote code execution or denial-of-service, particularly in deployments with DTLS enabled.

CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog following confirmation of active global exploitation. Threat actors have targeted government agencies, financial services, education, and legal sectors across North America and Europe. Security researchers have observed attackers attempting to gain root privileges, install web shells, and deploy anti-forensic measures to hide their tracks.

Experts warn that patching alone may not be sufficient if a system is already compromised. Security teams are advised to conduct forensic investigations for signs of persistence, such as unauthorized web shells or modified startup scripts, before applying updates. Organizations are urged to preserve logs and implement file integrity monitoring to detect potential intrusions.

Entities

CISA · Citrix · Cloud Software Group · NetScaler · Palo Alto Networks