Citrix confirms two NetScaler RCE zero-days exploited in attacks
Summary
Citrix has confirmed that two critical remote code execution vulnerabilities in its NetScaler products are actively being exploited in attacks. The company has released security updates to address these flaws, tracked as CVE-2026-88771 and CVE-2026-88772.
IFF Assessment
The active exploitation of critical vulnerabilities in widely used infrastructure products represents a significant threat to organizations, making this bad news for defenders.
Severity
The vulnerabilities allow for remote code execution, indicating a high impact. Given they are actively exploited zero-days in critical infrastructure, they are likely to be highly exploitable with a significant attack vector and impact.
Defender Context
Defenders need to prioritize patching or mitigating these critical NetScaler vulnerabilities immediately, as they are already being exploited in the wild. Organizations using NetScaler should conduct thorough investigations for any signs of compromise and ensure their security controls are robust enough to detect and prevent RCE attacks.