Citrix was criticized for waiting nearly two days to confirm active exploitation of two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, even as CERTs, vendors, and researchers warned customers through unofficial channels. The flaws can lead to remote code execution, and officials including CISA have added them to exploited-vulnerability tracking while defenders race to assess exposure and patch affected systems. #Citrix #NetScaler #CVE-2026-88771 #CVE-2026-88772 #CISA #GreyNoise #PaloAltoNetworks #watchTowr
Keypoints
- Citrix delayed public confirmation of active exploitation for almost two days.
- CVE-2026-88771 and CVE-2026-88772 are critical NetScaler zero-days rated 9.5 CVSS.
- The vulnerabilities can enable remote code execution, and one has a public proof-of-concept exploit.
- More than 50,000 publicly exposed NetScaler instances may be vulnerable.
- CISA added both flaws to its known exploited vulnerabilities catalog after Citrix confirmed the attacks.
Read More: https://cyberscoop.com/citrix-zero-days-delayed-disclosure/