Citrix Confirms Two Exploited NetScaler Zero-Days
Citrix confirmed that two actively exploited, previously unpatched vulnerabilities in its NetScaler products are being used in attacks and urged customers to install fixes in supported builds. The company identified the flaws as CVE-2026-88771 and CVE-2026-88772, assigning each a severity score of 9.5, according to a report published September 28. The confirmation followed warnings circulated among administrators and cybersecurity organizations the previous day, when technical details and official guidance were not publicly available. A report published September 27 said security teams and IT providers had privately advised some organizations to shut down NetScaler appliances while patches were being prepared. That account described the vulnerabilities as remote-code-execution flaws, but the reported technical information came in part from a circulating notice whose authenticity the Dutch National Cyber Security Center did not confirm. The notice was said to describe exploitation at multiple Citrix customers worldwide. It also reportedly said the agency did not know whether attacks were widespread.