Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings

Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
Citrix was criticized for waiting nearly two days to confirm active exploitation of two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, even as CERTs, vendors, and researchers warned customers through unofficial channels. The flaws can lead to remote code execution, and officials including CISA have added them to exploited-vulnerability tracking while defenders race to assess exposure and patch affected systems. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #CISA #GreyNoise #PaloAltoNetworks #watchTowr

Keypoints

  • Citrix delayed public confirmation of active exploitation for almost two days.
  • CVE-2026-88771 and CVE-2026-88772 are critical NetScaler zero-days rated 9.5 CVSS.
  • The vulnerabilities can enable remote code execution, and one has a public proof-of-concept exploit.
  • More than 50,000 publicly exposed NetScaler instances may be vulnerable.
  • CISA added both flaws to its known exploited vulnerabilities catalog after Citrix confirmed the attacks.

Read More: https://cyberscoop.com/citrix-zero-days-delayed-disclosure/