Citrix NetScaler zero-days exploited in the wild
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CISA warns two actively exploited zero-day RCE flaws among eight new Citrix NetScaler ADC/Gateway CVEs are being used by attackers globally.
CISA has issued an alert amplifying Citrix's disclosure of eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. Of these, CVE-2026-88771 and CVE-2026-88772 have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog; both are rated critical and can independently enable remote code execution. CISA states it has received reports and partner threat intelligence confirming active, global exploitation of at least these two flaws as zero-days prior to patch availability.
Because patching NetScaler appliances can require downtime and complex change management, CISA is urging administrators to prioritize checking for indicators of compromise before applying updates, since patching can destroy forensic evidence needed to determine if a device was already compromised. Citrix has published IOCs via NetScaler Console and a security bulletin covering all eight CVEs, along with guidance for handling suspected compromise.
Defenders running NetScaler ADC or Gateway should treat this as an urgent action item: review Citrix's security bulletin for affected versions and fixed builds, check appliances for compromise indicators using Citrix's provided guidance and NetScaler Console, preserve forensic evidence (logs, memory, configuration) if compromise is suspected, and then apply the security updates. Given the internet-facing nature of these appliances and their history as high-value targets for both APT and ransomware-affiliated actors, rapid triage and patching should be treated as a priority.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,104 reports from 154 sources, 2,663 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs