Tech News
← Home  ·  All topics

Cve 2026 88772

2 GoKawiil briefs on this topic

Citrix NetScaler zero-day exploited to plant web shells since early September

Mandiant and other security firms say attackers began exploiting an unpatched Citrix NetScaler flaw, tracked as CVE-2026-88772, in early September to install custom web shells and tunneling malware, gain root access, steal credentials, and move into internal networks. Victims span government, financial services, education, legal, and professional services organizations in North America and Europe. Citrix disclosed two related zero-days, CVE-2026-88771 and CVE-2026-88772, on Sunday and released patches after researchers including GreyNoise and watchTowr flagged active exploitation.

CISA sets Wednesday deadline for agencies to patch Citrix NetScaler flaws

CISA has directed federal agencies to fix two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, that Citrix confirmed are being actively exploited in zero-day attacks. Both bugs let unauthenticated attackers achieve remote code execution, with the first hitting default configurations and the second requiring DTLS, which is on by default for VPN virtual servers. Citrix has issued patches and shared indicators of compromise, after agencies like the Dutch NCSC had already been privately warning organizations to shut down affected appliances.