Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 43
2 unique sources, 2 articles

Summary

Hide ▲

Citrix confirmed active exploitation of NetScaler ADC and NetScaler Gateway zero-day flaws, exposing vulnerable appliances to unauthenticated remote code execution. The affected bugs are CVE-2026-88771 and CVE-2026-88772, and Citrix urged customers to install the updated versions immediately. CISA also added both CVEs to the KEV Catalog and ordered federal civilian agencies to remediate by September 30. The exploitation risk is highest for unmitigated NetScaler deployments and Internet-facing systems.

Related Happenings

Citrix NetScaler unpatched RCE zero-days actively exploited remote code execution flaw

Vulnerability
H score34 First: 27.09.2026 19:02 Last: 27.09.2026 19:02 Sources 1

About this happening: Two Citrix NetScaler remote code execution zero-days are being exploited in the wild, putting exposed appliances at immediate risk before fixes arrive. Private warning...

Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw

Vulnerability
H score34 First: 27.09.2026 10:47 Last: 27.09.2026 10:47 Sources 1

About this happening: Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used f...

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score54 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability
H score29 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...

Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)

Vulnerability
H score34 First: 27.08.2026 12:16 Last: 27.08.2026 12:16 Sources 1

About this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...

Timeline

  1. 28.09.2026 09:24 3 articles · 2h ago

    Citrix confirms active exploitation of NetScaler zero-days

    Initial Disclosure

    Citrix confirmed that CVE-2026-88771 and CVE-2026-88772 were being exploited in zero-day attacks against unmitigated NetScaler deployments, where unauthenticated attackers could obtain remote code execution on vulnerable NetScaler appliances, and urged customers to install the updated versions immediately.

    Show sources
  2. 28.09.2026 09:24 1 articles · 2h ago

    CISA adds NetScaler flaws to KEV Catalog and orders federal remediation

    Legal Policy Action Update

    CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by September 30 under Binding Operational Directive (BOD) 26-04.

    Show sources