#CVE-2026-88772
“This issue is understood to be separate from the vulnerabilities outlined below [CVE-2026-88771 and CVE-2026-88772].”

www.cyber.gov.au/about-us/vie...
www.cyber.gov.au
October 3, 2026 at 8:19 PM
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi...

Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
September 27, 2026 at 7:58 PM
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security www.helpnetsecurity.com/2026/09/28/c...
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) - Help Net Security
Citrix has patched two vulnerabilities (CVE-2026-88771, CVE-2026-88772) that been exploited in zero-day attacks to plant webshells.
www.helpnetsecurity.com
September 29, 2026 at 10:36 AM
@ncsc.gov.uk
Two NetScaler flaws are actively exploited; patch or isolate affected systems.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE-2026-88771 #CVE-2026-88772 #Citrix #ThreatIntel
Citrix NetScaler Exploitation
www.ncsc.gov.uk
September 28, 2026 at 8:10 PM
~Watchtowr~
In-the-wild pre-auth DTLS overflow enables RCE or DoS; patch immediately.
-
IOCs: CVE-2026-88772
-
#CVE-2026-88772 #Citrix #ThreatIntel
Citrix NetScaler DTLS RCE
labs.watchtowr.com
September 29, 2026 at 8:18 PM
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

www.helpnetsecurity.com/2026/09/30/c...

#Kyberturvallisuus #Kyber #Tilannekuva
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) - Help Net Security
Advanced threat actor exploited CVE-2026-88772, one of the two recently disclosed NetScaler zero-day flaws, for weeks.
www.helpnetsecurity.com
September 30, 2026 at 1:17 PM
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
www.bleepingcomputer.com
September 29, 2026 at 6:37 PM
⚠️ Alerte CERT-FR ⚠️
Les vulnérabilités CVE-2026-88771 et CVE-2026-88772 sont activement exploitées et permettent une RCE pré-authentification sur Citrix NetScaler ADC et Gateway.

www.cert.ssi.gouv.fr/alerte/CERTF...
September 28, 2026 at 9:00 AM
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)(国家支援型とみられる攻撃者、NetScalerゼロデイを9月初旬から悪用) #HelpNetSecurity (Sep 30)
www.helpnetsecurity.com/2026/09/30/c...
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) - Help Net Security
Advanced threat actor exploited CVE-2026-88772, one of the two recently disclosed NetScaler zero-day flaws, for weeks.
www.helpnetsecurity.com
October 1, 2026 at 2:38 AM
Citrix patched two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, after weeks-long attacks used for unauthenticated RCE, root access, and web shells. Over 100 victims may be affected. #NetScaler #Mandiant #Europe
Government, Finance Orgs Targeted In Weeks-Long NetScaler Zero-Day Attacks
Google’s Mandiant and GTIG reported ongoing exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which attackers used to gain root access and deploy web shells. The campaign, active since at least early September, affected organizations across multiple sectors in North America and Europe, with more than 100 victims potentially impacted. #CVE-2026-88771 #CVE-2026-88772...
www.hendryadrian.com
September 30, 2026 at 5:15 PM
Citrix NetScaler 0-day active for weeks

Citrix NetScaler vulnerabilities (CVE-2026-88771, -88772) were actively exploited against critical sectors for weeks before disclosure. Users must check for compromise *before* patching.
September 30, 2026 at 11:05 AM
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
www.cyber.gc.ca
September 27, 2026 at 8:39 PM
~Cisa~
CISA reports active exploitation of two Citrix NetScaler vulnerabilities and urges rapid remediation.
-
IOCs: CVE-2026-88771, CVE-2026-88772
-
#CVE-2026-88771 #CVE-2026-88772 #ThreatIntel
CISA Adds Two Citrix NetScaler CVEs to KEV
www.cisa.gov
September 27, 2026 at 8:02 PM
Citrix says two critical NetScaler vulnerabilities are being actively exploited.

CVE-2026-88771 enables unauthenticated RCE across all deployments.

CVE-2026-88772 can lead to RCE or DoS where DTLS is enabled.

cyberupdates365.com/citrix-netsc...

#Cybersecurity #Citrix #NetScaler
Citrix NetScaler CVE-2026-88771, 88772 RCE Exploited
Citrix confirms active exploitation of CVE-2026-88771 and CVE-2026-88772, two critical NetScaler RCE flaws affecting ADC and Gateway systems.
cyberupdates365.com
September 28, 2026 at 1:25 PM
Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 were used to deploy web shells, tunneling malware, and steal credentials in attacks across North America and Europe. #Citrix #NorthAmerica #Europe
Hackers Exploit Citrix NetScaler Zero-day To Deploy Web Shells
Attackers exploited Citrix NetScaler CVE-2026-88772 and CVE-2026-88771 zero-days to deploy web shells, tunneling malware, steal credentials, and move deeper into internal networks. Mandiant and GreyNoise say the campaign affected organizations across North America and Europe, with persistent post-exploitation tactics including root access abuse and the use of WHIPSHOT and SLAPSHOT. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #Mandiant #GreyNoise #WHIPSHOT #SLAPSHOT
www.hendryadrian.com
September 29, 2026 at 10:15 PM
Attacks exploiting Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 enable remote code execution, root access, web-shell deployment, and internal network compromise.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 12:54 PM
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day a…
#hackernews #news
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped up on Reddit on Friday, fueled by warnings from IT suppliers, who apparently got the information from the Dutch National Cyber Security Center (NCSC-NL). According to security researcher Kevin Beaumont, European government sources have been warning …
www.helpnetsecurity.com
September 29, 2026 at 5:11 AM
Mandiant and GTIG report active exploitation of Citrix NetScaler ADC/Gateway via CVE-2026-88772 and CVE-2026-88771, with custom tools, root access, persistence, and hidden C2 in HTTP headers. #CitrixNetScaler #WHIPSHOT #SLAPSHOT
Defending Against Active Exploitation Of Citrix NetScaler ADC And Gateway Appliances
Mandiant and GTIG identified active exploitation of CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway, with intrusions using custom tooling to gain root access, persist, and move into internal networks. The campaign deployed WHIPSHOT and SLAPSHOT to hide C2 in HTTP headers, proxy traffic for reconnaissance and credential theft, and abuse modified web server settings, while Citrix also warned that CVE-2026-88771 is being actively exploited. #CVE-2026-88772 #CVE-2026-88771 #CitrixNetScaler #WHIPSHOT #SLAPSHOT
www.hendryadrian.com
September 30, 2026 at 5:15 AM
Zusätzlich sehr nützliche Betriebs- und Incident-Response-Hinweise gibt es hier:
Citrix Patches Two Exploited NetScaler RCE Zero-Days - Cyber Kendra
Citrix patches exploited NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5. Update to 14.1-73.37 or 13.1-64.23 now.
www.cyberkendra.com
September 27, 2026 at 5:33 PM
They have. CVE 2026-88771 and -88772. Both 9.5

support.citrix.com/support-home...
Loading...
support.citrix.com
September 27, 2026 at 4:40 PM
CVE-2026-88772: Citrix NetScaler Zero-Day Exploited, PoC Details Emerge(Citrix NetScalerゼロデイCVE-2026-88772が実悪用、PoC詳細も公開) #SecurityOnline (Sep 30)
securityonline.info/citrix-netsc...
https://securityonline.info/citrix-netscaler-cve-2026-88772-poc-exploited/
securityonline.info
October 1, 2026 at 2:40 AM