DEV Community

Mark0
Mark0

Posted on

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

⚠️ Region Alert: UAE/Middle East

Citrix has reported active exploitation of two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway devices. Both vulnerabilities carry a CVSS v4.0 score of 9.5, posing a significant risk through unauthenticated remote code execution (RCE) and denial of service (DoS) via DTLS configurations. Unit 42 has identified over 50,000 exposed instances globally, emphasizing the urgency for immediate remediation.

Security teams are advised to update their Citrix software to the latest versions immediately. Interim guidance includes isolating vulnerable systems, capturing forensic evidence such as instance snapshots and core dumps, and hunting for signs of suspicious administrative sessions or unexplained logging gaps. Organizations are cautioned that patching alone may not remove attackers who have already established persistence within a network.


Read Full Article

Top comments (0)