Unit42

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Executive Summary

Unit 42 is aware of possible zero-day activity against NetScaler devices. Citrix reports that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild. No further details are currently available about the exploit activity. 

  • CVE-2026-88771 is a remote code execution (RCE) vulnerability that fails to properly validate input and allows an unauthenticated actor to run commands against NetScaler ADC and NetScaler Gateway systems 
  • CVE-2026-88772 is a memory overflow vulnerability that can lead to a remote code execution (RCE) or denial of service (DoS) on the Datagram Transport Layer Security (DTLS) configuration on NetScaler ADC and NetScaler Gateway systems

Both vulnerabilities have a CVSS v4.0 base score of 9.5. 

The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

Vulnerabilities DiscussedCVE-2026-88771, CVE-2026-88772

Interim Guidance

Unit 42 recommends that customers update their Citrix software to the latest versions as soon as possible, as well as following the recommendations:

  • Confirm exposure following the “Steps to determine if an appliance meets the CVE preconditions” section of the Citrix Security Advisory for these vulnerabilities
  • Isolate the vulnerable systems from the network
  • Preserve evidence by capturing the following:
    • A NetScaler VPX instance snapshot
    • Logs on remote syslog servers and NetScaler Console
    • A technical support bundle 
    • A packet engine core dump 
  • Hunt for the following:
    • Signs of suspicious administrative sessions
    • Unexpected outbound connections 
    • Unexplained gaps in logging

Note: These are not tactics, techniques and procedures (TTPs) we have observed specifically related to these vulnerabilities. They should be seen as general hunting guidance until more is known about the exploitation activity identified by Citrix in their advisory.  

  • Update and patch to the latest versions 

Note: Updating and patching will not remove access for attackers that have already established persistence within a compromise the network.  

As of Sept. 27, 2026, Palo Alto Networks Cortex Xpanse has identified the presence of over 50,277 exposed instances potentially vulnerable to these CVEs based on our telemetry.

If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: 

  • North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
  • UK: +44.20.3743.3660
  • Europe and Middle East: +31.20.299.3130
  • Asia: +65.6983.8730
  • Japan: +81.50.1790.0200
  • Australia: +61.2.4062.7950
  • India: 000 800 050 45107
  • South Korea: +82.080.467.8774

Additional References



Source link