Published Monday, September 28, 2026 at 11:58 AM PT

<strong>BREAKING — NetScaler Zero Days Actively Exploited in the Wild</strong>

BLUF: Citrix NetScaler devices are under active exploitation for CVE-2026-88771 and CVE-2026-88772. Unit 42 confirms both vulnerabilities are being weaponized in the wild. Organizations running NetScaler should audit for signs of compromise and apply patches immediately when available. Status of public patches is not yet confirmed from provided material.

DETAILS

  • Unit 42 Palo Alto Networks has confirmed active, in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler
  • Citrix has publicly acknowledged both vulnerabilities; disclosure status and patch availability are not specified in available material
  • Unit 42 reports “possible 0-day activity”—indicating either pre-disclosure exploitation or rapid weaponization post-disclosure; exact timeline unclear from provided brief
  • No technical details (CVSS score, affected versions, attack vector) are included in the provided summary
  • Threat actor identity and specific targeting patterns are not disclosed in available material

IMPACT

Organizations running Citrix NetScaler are directly at risk. NetScaler is widely deployed in enterprise environments as a load balancer, application delivery controller, and gateway. Successful exploitation could enable unauthorized access, lateral movement, and data exfiltration. Scope of active compromise is unknown—no victim count or targeted sectors specified in available material.

RECOMMENDED ACTIONS

  1. Immediate: Inventory all NetScaler deployments in your environment
  2. Urgent: Monitor for available security patches from Citrix; apply when released
  3. Now: Check logs for exploitation attempts (CVE identifiers and indicators of compromise will be published as analysis matures)
  4. Parallel: Contact Citrix support for interim mitigations if patches are not yet available
  5. Alert: Brief your security operations and incident response teams

SOURCES

Unit 42 Palo Alto Networks Threat Brief (2026-09-28): “NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild”


STATUS: DEVELOPING — Additional technical details, indicators of compromise, and patch status expected from Citrix and Unit 42 within 24–48 hours. Re-check for IOCs and CVSS assessments.


Recent high-severity events at publish time:

Recent high-severity events