← All articles

Citrix confirms two NetScaler remote code execution zero-days exploited in active attacks

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks, and released fixes. These are the same zero-days that researchers, IT providers, and national cyber agencies warned about privately over the weekend, with some advising immediate NetScaler shutdowns. Organizations commonly deploy NetScaler as internet-facing edge devices for remote access and application delivery, so compromising one gives attackers a foothold at the network perimeter and a potential path to internal systems without first landing on an internal endpoint. CISA added the flaws to its Known Exploited Vulnerabilities catalog with a near-term federal patch deadline.

Check
Identify all internet-facing NetScaler appliances, apply Citrix's fixed builds immediately, and hunt for compromise indicators given confirmed active exploitation.
Affected
Unpatched internet-facing NetScaler appliances face active exploitation of two remote code execution zero-days, handing attackers a foothold at the network perimeter.
Fix
Patch NetScaler to Citrix's fixed versions now, restrict management exposure, review sessions and logs, and treat exposed devices as potentially compromised.