Citrix NetScaler zero-days exploited before disclosure; emergency patching urged
Rapid7 reports that two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before Citrix disclosed them; CISA added both to its Known Exploited Vulnerabilities catalog. The first can enable remote code execution in default configurations, while the second requires DTLS to be enabled. Rapid7 recommends urgently applying the available updates and investigating vulnerable appliances for signs of compromise.
What changed Citrix’s September 27 disclosure made the vulnerabilities public after attackers had already exploited both as zero-days.
Why it matters NetScaler operators cannot treat patching alone as incident closure: Rapid7 recommends also checking vulnerable appliances for evidence of compromise.
What to watch next Rapid7 expects authenticated vulnerability checks in its September 28 content release; availability is expected, not confirmed in this report.
Rapid7 ↗