Citrix confirms two NetScaler zero-days exploited worldwide
CVE-2026-88771 and CVE-2026-88772 remain under confirmed global exploitation against internet-facing ADC/NetScaler infrastructure, including VPN and authentication services. Fixes are available, but organizations must assume exposed appliances may be compromised, investigate before and after patching, review IOCs, and rotate credentials, sessions, certificates, and tokens.
Sources (3)
Updated Sep 28, 2026