Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Citrix Confirms Two Exploited NetScaler Zero-Days

Published 28 September 2026

Citrix confirmed that two actively exploited, previously unpatched vulnerabilities in its NetScaler products are being used in attacks and urged customers to install fixes in supported builds. The company identified the flaws as CVE-2026-88771 and CVE-2026-88772, assigning each a severity score of 9.5, according to a report published September 28. The confirmation followed warnings circulated among administrators and cybersecurity organizations the previous day, when technical details and official guidance were not publicly available. A report published September 27 said security teams and IT providers had privately advised some organizations to shut down NetScaler appliances while patches were being prepared. That account described the vulnerabilities as remote-code-execution flaws, but the reported technical information came in part from a circulating notice whose authenticity the Dutch National Cyber Security Center did not confirm. The notice was said to describe exploitation at multiple Citrix customers worldwide. It also reportedly said the agency did not know whether attacks were widespread.

0:00 / 0:00