Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
- The Cybersecurity and Infrastructure Security Agency added two critical Citrix NetScaler vulnerabilities to its known exploited list on Sunday after Citrix confirmed active attacks and released security patches.
- Attackers are actively exploiting CVE-2026-88771 and CVE-2026-88772, critical flaws affecting all NetScaler ADC and Gateway deployments that allow remote code execution and command injection on unmitigated devices.
- Palo Alto Networks identified more than 50,000 potentially vulnerable NetScaler instances as of Sunday, while both flaws score 9.5 out of 10 for severity, prompting CISA to mandate federal agency remediation.
- Ben Harris, CEO at watchTowr, called Citrix's delayed disclosure 'unconscionably irresponsible' in a LinkedIn post, as security professionals criticized the vendor for remaining silent for more than 36 hours during active exploitation.
- Security researcher Kevin Beaumont wrote that attackers are 'probably nation state aligned,' while CISA warned organizations to check for compromise before patching, as updates can erase critical forensic evidence.
49 Articles
49 Articles
Sophisticated Citrix Zero-Day Malware Targets Governments and Banks Worldwide
Sophisticated custom malware exploiting a Citrix zero-day vulnerability has targeted government agencies, banks, and professional services firms worldwide. The highly adapted, memory-resident tools bypass detection, maintain persistence, and exfiltrate sensitive data while mimicking legitimate traffic. The attacks highlight the risks of perimeter devices and the need for enhanced security measures.
A vulnerability in the security software Citrix has once again caused problems for government organizations and hospitals. Following a warning from the National Cyber Security Center (NCSC), various institutions have shut down their systems as a precaution. According to tech expert Bert Hubert, warnings about an impending leak have been issued for weeks, but Citrix took no action. "You hope that this is the straw that breaks the camel's back."
Hackers exploit two critical Citrix NetScaler zero-days
Attackers are exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway. Companies use the devices to give staff remote access to internal networks. Citrix confirmed the attacks in a security bulletin on Sunday and released fixes. Both flaws were exploited before a patch existed. “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments […] This story continues at The Next Web
The problems facing the company Citrix last weekend were exploited at least twice, the National Cyber Security Centre (NCSC) confirms. The central government and various hospitals, among others, use Citrix's digital systems. The ‘vulnerabilities’ in the system could, for example, make it possible to gain remote access to the system.
Coverage Details
Bias Distribution
- 57% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

















