⚠️ Region Alert: UAE/Middle East
Unit 42 has reported active zero-day exploitation of Citrix NetScaler ADC and Gateway devices involving two critical vulnerabilities: CVE-2026-88771 and CVE-2026-88772. These vulnerabilities carry a high CVSS v4.0 score of 9.5, allowing for unauthenticated remote code execution (RCE) and denial of service (DoS) attacks. Telemetry indicates over 50,000 instances are currently exposed and potentially vulnerable to these flaws.
Organizations are urged to update Citrix software immediately and follow interim security guidance. Recommended actions include isolating vulnerable systems from the network, preserving evidence through snapshots and logs, and hunting for signs of suspicious administrative sessions or unexpected outbound connections. It is crucial to note that patching alone will not remove attackers who have already established persistence within a compromised network.
Top comments (0)