#CVE-2026-88771
“This issue is understood to be separate from the vulnerabilities outlined below [CVE-2026-88771 and CVE-2026-88772].”

www.cyber.gov.au/about-us/vie...
www.cyber.gov.au
October 3, 2026 at 8:19 PM
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi...

Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
September 27, 2026 at 7:58 PM
A timeline of Citrix NetScaler CVE-2026-88771, from the CVE reservation on Sep 10 to public disclosure on Sep 27, including the exploitation attempts GreyNoise observed on Sep 24.

🔗 Full analysis: www.greynoise.io/blog/swarmin...
September 29, 2026 at 3:02 PM
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security www.helpnetsecurity.com/2026/09/28/c...
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security
Citrix has patched two vulnerabilities (CVE-2026-88771, CVE-2026-88772) that been exploited in zero-day attacks to plant webshells.
www.helpnetsecurity.com
September 29, 2026 at 10:36 AM
@ncsc.gov.uk
Two NetScaler flaws are actively exploited; patch or isolate affected systems.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE-2026-88771 #CVE-2026-88772 #Citrix #ThreatIntel
Citrix NetScaler Exploitation
www.ncsc.gov.uk
September 28, 2026 at 8:10 PM
Citrix flaws under attack, Chinese espionage targets 100+ U.K. academics, Warlock hits Iberia.

• CVE-2026-88771/88772 actively exploited (news/7207a6cc)

5 sources verified · hackingallthethings.com
#infosec #threatintel #cybersecurity #CVE #APT
October 4, 2026 at 6:01 AM
At The Edge Clear: September 21 – 28, 2026
An adversary tried Citrix NetScaler CVE-2026-88771 against a GreyNoise Swarm participant sensor more than three days before public disclosure.

🔗 www.greynoise.io/resources/at...
September 30, 2026 at 2:30 PM
⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

www.cert.ssi.gouv.fr/alerte/CERTF...
September 28, 2026 at 9:00 AM
Citrix NetScaler Active Exploitation via CVE-2026-88771
wolf-tools/pack_alerts/202609-citrix-netscaler-active-exploitation-cve-2026-88771 at main · rtkwlf/wolf-tools
Tools and scripts by Arctic Wolf. Contribute to rtkwlf/wolf-tools development by creating an account on GitHub.
github.com
October 1, 2026 at 1:12 AM
Citrix NetScaler 0-day active for weeks

Citrix NetScaler vulnerabilities (CVE-2026-88771, -88772) were actively exploited against critical sectors for weeks before disclosure. Users must check for compromise *before* patching.
September 30, 2026 at 11:05 AM
Wondering why Citrix NetScalers are always beset with critical RCE exploits and then I read this deep-dive on one of the most recent ones, it's fucking RCE via log injection. Incredible. cert.europa.eu/blog/taking-...
Taking 'execute logging' a bit too literally - CVE-2026-88771
Taking 'execute logging' a bit too literally - CVE-2026-88771
cert.europa.eu
October 2, 2026 at 1:03 PM
Citrix patched two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, after weeks-long attacks used for unauthenticated RCE, root access, and web shells. Over 100 victims may be affected. #NetScaler #Mandiant #Europe
Government, Finance Orgs Targeted In Weeks-Long NetScaler Zero-Day Attacks
Google’s Mandiant and GTIG reported ongoing exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which attackers used to gain root access and deploy web shells. The campaign, active since at least early September, affected organizations across multiple sectors in North America and Europe, with more than 100 victims potentially impacted. #CVE-2026-88771 #CVE-2026-88772...
www.hendryadrian.com
September 30, 2026 at 5:15 PM
CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validat…

https://planetbriefing.com/events/cve-2026-88771-citrix-netscaler-improper-input-validation-vulnerability-784752551976

#Technology #UnitedStates
September 28, 2026 at 1:55 AM
Citrix says two critical NetScaler vulnerabilities are being actively exploited.

CVE-2026-88771 enables unauthenticated RCE across all deployments.

CVE-2026-88772 can lead to RCE or DoS where DTLS is enabled.

cyberupdates365.com/citrix-netsc...

#Cybersecurity #Citrix #NetScaler
Citrix NetScaler CVE-2026-88771, 88772 RCE Exploited
Citrix confirms active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical NetScaler RCE flaws affecting ADC and Gateway systems.
cyberupdates365.com
September 28, 2026 at 1:25 PM
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
www.cyber.gc.ca
September 27, 2026 at 8:39 PM
~Cisa~
CISA reports active exploitation of two Citrix NetScaler vulnerabilities and urges rapid remediation.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE-2026-88771 #CVE-2026-88772 #ThreatIntel
CISA Adds Two Citrix NetScaler CVEs to KEV
www.cisa.gov
September 27, 2026 at 8:02 PM
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were used to deploy web shells, tunneling malware, and steal credentials in attacks across North America and Europe. #Citrix #NorthAmerica #Europe
Hackers Exploit Citrix NetScaler Zero-day To Deploy Web Shells
Attackers exploited Citrix NetScaler CVE-2026-88772 and CVE-2026-88771 zero-days to deploy web shells, tunneling malware, steal credentials, and move deeper into internal networks. Mandiant and GreyNoise say the campaign affected organizations across North America and Europe, with persistent post-exploitation tactics including root access abuse and the use of WHIPSHOT and SLAPSHOT. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #Mandiant #GreyNoise #WHIPSHOT #SLAPSHOT
www.hendryadrian.com
September 29, 2026 at 10:15 PM
Attacks exploiting Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 enable remote code execution, root access, web-shell deployment, and internal network compromise.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 12:54 PM
Mandiant and GTIG report active exploitation of Citrix NetScaler ADC/Gateway via CVE-2026-88772 and CVE-2026-88771, with custom tools, root access, persistence, and hidden C2 in HTTP headers. #CitrixNetScaler #WHIPSHOT #SLAPSHOT
Defending Against Active Exploitation Of Citrix NetScaler ADC And Gateway Appliances
Mandiant and GTIG identified active exploitation of CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway, with intrusions using custom tooling to gain root access, persist, and move into internal networks. The campaign deployed WHIPSHOT and SLAPSHOT to hide C2 in HTTP headers, proxy traffic for reconnaissance and credential theft, and abuse modified web server settings, while Citrix also warned that CVE-2026-88771 is being actively exploited. #CVE-2026-88772 #CVE-2026-88771 #CitrixNetScaler #WHIPSHOT #SLAPSHOT
www.hendryadrian.com
September 30, 2026 at 5:15 AM
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day a…
#hackernews #news
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped up on Reddit on Friday, fueled by warnings from IT suppliers, who apparently got the information from the Dutch National Cyber Security Center (NCSC-NL). According to security researcher Kevin Beaumont, European government sources have been warning …
www.helpnetsecurity.com
September 29, 2026 at 5:11 AM
Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier:
Citrix Patches Two Exploited NetScaler RCE Zero-Days - Cyber Kendra
Citrix patches exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5. Update to 14.1-73.37 or 13.1-64.23 now.
www.cyberkendra.com
September 27, 2026 at 5:33 PM