Citrix NetScaler flaws exploited as zero-days, CISA confirms global activity
Rapid7 reports that two critical NetScaler ADC and Gateway remote-code-execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild before Citrix disclosed them. CISA added both to its Known Exploited Vulnerabilities catalog; the first affects default configurations, while the second requires DTLS to be enabled. Rapid7 recommends emergency updates and checking vulnerable appliances for signs of compromise.
What changed The September 27 disclosure followed exploitation, rather than preceding it, so defenders received public notice after attacks had already begun.
Why it matters NetScaler operators cannot assume that avoiding optional features removes their exposure: CVE-2026-88771 permits remote code execution in vulnerable default deployments.
What to watch next Rapid7’s recommended next steps are emergency patching and investigation for existing compromise; installing an update alone does not answer whether an appliance was already breached.
Rapid7 ↗