NetScaler Zero Days CVE-2026-88771 & CVE-2026-88772 Exploited in the Wild

Executive Summary

Unit 42 reports that Citrix’s NetScaler devices are being targeted by two zero‑day vulnerabilities, CVE‑2026‑88771 and CVE‑2026‑88772, which have already been exploited in the wild. The attacks allow attackers to execute arbitrary code on affected systems, potentially compromising network infrastructure.


Intelligence Metadata - Source Publisher: Unit 42 (Palo Alto) - Published Date: 2026-09-28T15:02:04+00:00 - Category: threat-intel

Original Description: Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

"The beginning of knowledge is the discovery of something we do not understand."

— Frank Herbert
Source: Unit 42 (Palo Alto)