
🛡️ **BREAKING — NetScaler Zero Days Actively Exploited in the Wild**
Published Monday, September 28, 2026 at 11:58 AM PT BLUF: Citrix NetScaler devices are under active exploitation for CVE-2026-88771 and CVE-2026-88772. Unit 42 confirms both vulnerabilities are being weaponized in the wild. Organizations running NetScaler should audit for signs of compromise and apply patches immediately when available. Status of public patches is not yet confirmed from provided material. DETAILS Unit 42 Palo Alto Networks has confirmed active, in-the-wild exploitation of CVE-2026-88771 and CVE-2026-88772 affecting Citrix NetScaler Citrix has publicly acknowledged both vulnerabilities; disclosure status and patch availability are not specified in available material Unit 42 reports “possible 0-day activity”—indicating either pre-disclosure exploitation or rapid weaponization post-disclosure; exact timeline unclear from provided brief No technical details (CVSS score, affected versions, attack vector) are included in the provided summary Threat actor identity and specific targeting patterns are not disclosed in available material IMPACT ...