Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical NetScaler RCE Zero‑Days (CVE‑2026‑88771/88772) Actively Exploited – Immediate Patch Required

Citrix confirmed two critical remote‑code‑execution zero‑days in NetScaler ADC/Gateway (CVSS 9.5) are being exploited in the wild, affecting all deployments. Organizations must prove timely patching and perimeter control to satisfy audit and regulatory expectations.

LiveThreat™ Intelligence · 📅 September 27, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Critical NetScaler RCE Zero‑Days (CVE‑2026‑88771 & CVE‑2026‑88772) Actively Exploited – Immediate Patch Required

What It Is — Citrix has confirmed two critical remote‑code‑execution vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances (CVE‑2026‑88771, CVE‑2026‑88772). Both receive a CVSS 9.5 rating and can be triggered without any authentication.

Exploitability — Active exploitation is verified by Citrix and multiple threat‑intel sources; proof‑of‑concept code is already circulating. No fix existed until Citrix issued bulletin CTX697096.

Affected Products — All NetScaler ADC and NetScaler Gateway deployments, including those running with default configurations. The DTLS‑enabled variant is also vulnerable.

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous vulnerability management and rapid patch deployment as a core control objective.
  • Demonstrates that perimeter‑facing devices must be part of an auditable asset inventory and evidence‑rich remediation process.
  • Reinforces the importance of maintaining defensible logs that prove remediation timelines to regulators, partners, and auditors.

Recommended Actions

  • Deploy the CTX697096 security updates to every NetScaler appliance without delay.
  • Verify patch status through automated inventory tools and retain installation logs for audit trails.
  • Integrate NetScaler scanning into your continuous control‑mapping program to ensure future gaps are detected early.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →