Citrix NetScaler Zero-Days Exploited Globally
Unauthenticated NetScaler CVE-2026-88771 and CVE-2026-88772 have reportedly been exploited worldwide for weeks against VPN and application-delivery infrastructure. Web shells, anti-forensics, device-specific persistence, and unreliable detection after credential rotation make exposed appliances potential intrusion pivots; teams should verify SAML-related exposure, preserve evidence, patch urgently, and hunt for compromise.
Sources (2)
Updated Oct 6, 2026