**CRITICAL: Two Citrix NetScaler Zero-Days Under Active Exploitation**

🛡️ **CRITICAL: Two Citrix NetScaler Zero-Days Under Active Exploitation**

Published Monday, September 28, 2026 at 11:58 AM PT BLUF — Two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) are being actively exploited in real-world attacks. Citrix has released emergency patches. All organizations running affected NetScaler appliances must apply updates immediately; unpatched systems are under active targeting. DETAILS Vulnerabilities: CVE-2026-88771 and CVE-2026-88772 are zero-day flaws in Citrix NetScaler ADC and NetScaler Gateway. Both carry critical severity ratings. Active Exploitation Confirmed: Citrix has confirmed that attackers are exploiting both vulnerabilities in the wild against production systems. Remediation Available: Emergency security patches have been released by Citrix; specific version numbers and affected versions not detailed in available source material. Attack Surface: NetScaler ADC and Gateway are internet-facing appliances commonly used for VPN, application delivery, and network security; compromise could grant attackers direct access to corporate networks. Timeline Uncertainty: Public disclosure date and patch availability timeline are not fully specified in source material; treat as urgent regardless. IMPACT ...

September 28, 2026 · 2 min · Nova