CiberLATAMbywhalemate

Citrix NetScaler adds two exploited zero-days

CVE-2026-88771 and CVE-2026-88772 were used to plant web shells in NetScaler. CISA also added CVE-2026-88779 to KEV.

Whalemate Labs · AI-assisted researchPublished:3 min read

Citrix NetScaler ADC and NetScaler Gateway have been hit by a chain of incidents involving several flaws already under active exploitation. Among them are CVE-2026-88771 and CVE-2026-88772, used in zero-day attacks to plant web shells, and CVE-2026-88779, which CISA added to its Known Exploited Vulnerabilities catalog after reports of global exploitation.

Citrix NetScaler ADC and NetScaler Gateway have accumulated several actively exploited flaws in recent days, with direct impact on edge devices and exposed services. Among them are CVE-2026-88771 and CVE-2026-88772, used in zero-day attacks to plant web shells on compromised systems, and CVE-2026-88779, which CISA added to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

What was confirmed about CVE-2026-88771 and CVE-2026-88772?

Both flaws were confirmed to have been exploited before fixed builds were available, and they were used in zero-day attacks against NetScaler ADC and NetScaler Gateway. Help Net Security reported that attackers managed to plant web shells on compromised devices. Citrix also released bulletin CTX697096 covering eight vulnerabilities in the platform.

An independent technical analysis from the University of York said CVE-2026-88771 allows unauthenticated remote command execution and affects default deployments. CVE-2026-88772 is a memory overflow that requires DTLS to be enabled and can lead to remote code execution or denial of service. The same source said the fixed builds are NetScaler ADC/Gateway 14.1-73.37 or later, 13.1-64.23 or later, and the corresponding FIPS/NDcPP versions.

What happened with CVE-2026-88779?

CVE-2026-88779 was added by CISA to the KEV catalog after reports confirmed global exploitation of a recent Citrix NetScaler vulnerability. SecurityWeek said it affects instances configured as a SAML service provider or identity provider, and that Citrix classified it as a high-severity memory overflow issue.

The same coverage added that CISA set October 7, 2026, as the remediation deadline for US federal agencies. The Record also reported that CISA warned of global exploitation and that Citrix later published a security notice and blog post about CVE-2026-88779.

What other active flaws appeared in the same period?

The same wave included other vulnerabilities confirmed as actively exploited in widely deployed products. Exploit Radar listed CVE-2026-76504 as actively exploited in Cisco Catalyst SD-WAN and CVE-2026-104286 as actively exploited in Fortinet FortiMail. Cybervoc.io also said Fortinet disclosed CVE-2026-104286 as a critical FortiMail flaw with active exploitation.

That was joined by CVE-2026-65660, a Microsoft SharePoint Server vulnerability that CISA added to the KEV catalog after confirming active exploitation, according to a Spanish-language report from Quasa. The Register also reported that the critical authentication flaw in Rejetto HTTP File Server was seen under attack and can lead to full admin access and remote code execution.

SocPrime added that CVE-2026-35273 is being exploited by UNC6240, also identified as ShinyHunters, against Oracle PeopleSoft. In the same set of incidents, Help Net Security and ThreatMon placed Citrix NetScaler among the systems hit hardest by pre-patch exploitation chains.

Sources

View all