Skip to main content
See every side of every news story
Published • loading... • Updated

Citrix Patches Actively Exploited NetScaler Zero-Days After a Weekend of Unofficial Warnings

Citrix said the flaws let attackers run commands without logging in or trigger remote code execution, and both score 9.5 out of 10 for severity.

  • The Cybersecurity and Infrastructure Security Agency added two critical Citrix NetScaler vulnerabilities to its known exploited list on Sunday after Citrix confirmed active attacks and released security patches.
  • Attackers are actively exploiting CVE-2026-88771 and CVE-2026-88772, critical flaws affecting all NetScaler ADC and Gateway deployments that allow remote code execution and command injection on unmitigated devices.
  • Palo Alto Networks identified more than 50,000 potentially vulnerable NetScaler instances as of Sunday, while both flaws score 9.5 out of 10 for severity, prompting CISA to mandate federal agency remediation.
  • Ben Harris, CEO at watchTowr, called Citrix's delayed disclosure 'unconscionably irresponsible' in a LinkedIn post, as security professionals criticized the vendor for remaining silent for more than 36 hours during active exploitation.
  • Security researcher Kevin Beaumont wrote that attackers are 'probably nation state aligned,' while CISA warned organizations to check for compromise before patching, as updates can erase critical forensic evidence.
Insights by Ground AI

12 Articles

Lean Right

A vulnerability in the security software Citrix has once again caused problems for government organizations and hospitals. Following a warning from the National Cyber Security Center (NCSC), various institutions have shut down their systems as a precaution. According to tech expert Bert Hubert, warnings about an impending leak have been issued for weeks, but Citrix took no action. "You hope that this is the straw that breaks the camel's back."

·Amsterdam, Netherlands (Kingdom of the)
Read Full Article
Right

The problems facing the company Citrix last weekend were exploited at least twice, the National Cyber Security Centre (NCSC) confirms. The central government and various hospitals, among others, use Citrix's digital systems. The ‘vulnerabilities’ in the system could, for example, make it possible to gain remote access to the system.

·Apeldoorn, Netherlands (Kingdom of the)
Read Full Article
Lean Left

At several hospitals, patients were unable to access their data last weekend, and civil servants working from home are experiencing difficulties logging in. In 2025, hackers gained access to the Public Prosecution Service's virtual work environment via a vulnerability in Citrix.

·Amsterdam, Netherlands (Kingdom of the)
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 40% of the sources lean Left, 40% of the sources lean Right
40% Right

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

iTnews broke the news on Monday, September 28, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal