Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Summary
CISA is highlighting eight critical zero-day vulnerabilities affecting Citrix NetScaler ADC and Gateway products, with CVE-2026-88771 and CVE-2026-88772 already being actively exploited by threat actors globally. These vulnerabilities can independently enable remote code execution, posing a significant risk to organizations. CISA urges users to assess exposure, prioritize mitigation, and review Citrix's advisories and indicators of compromise, advising caution to preserve forensic evidence before patching.
IFF Assessment
The article reports on critical zero-day vulnerabilities that are actively being exploited, representing a direct threat to organizations and their data.
Severity
The article describes critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) that enable remote code execution and are actively exploited, indicating a high severity and exploitability.
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching these critical vulnerabilities in Citrix NetScaler appliances immediately, as they are known to be actively exploited. Organizations should also review their systems for signs of compromise and ensure they have robust incident response plans in place to handle potential breaches arising from these exploits.