Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

Summary

Citrix NetScaler appliances are reportedly being actively exploited by threat actors exploiting two newly disclosed vulnerabilities, CVE-2026-88771 and CVE-2026-88772. These vulnerabilities, if exploited, could allow for significant impact on affected systems.

IFF Assessment

FOE

The active exploitation of critical vulnerabilities in widely used network infrastructure directly threatens organizations, making it bad news for defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating Citrix NetScaler appliances immediately given the active exploitation. Organizations need to be vigilant about potential intrusions and monitor network traffic for signs of compromise related to these CVEs.

Read Full Story →