DEV Community

Mark0
Mark0

Posted on

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

⚠️ Region Alert: UAE/Middle East

Unit 42 has reported active zero-day exploitation of Citrix NetScaler ADC and Gateway devices involving two critical vulnerabilities: CVE-2026-88771 and CVE-2026-88772. These vulnerabilities carry a high CVSS v4.0 score of 9.5, allowing for unauthenticated remote code execution (RCE) and denial of service (DoS) attacks. Telemetry indicates over 50,000 instances are currently exposed and potentially vulnerable to these flaws.

Organizations are urged to update Citrix software immediately and follow interim security guidance. Recommended actions include isolating vulnerable systems from the network, preserving evidence through snapshots and logs, and hunting for signs of suspicious administrative sessions or unexpected outbound connections. It is crucial to note that patching alone will not remove attackers who have already established persistence within a compromised network.


Read Full Article

Top comments (0)