{"schema":"hottub-news/story/v1","story":"st_iypv2l44sueeyaatxmpq","title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild","title_en":null,"outlets":3,"brief":null,"page":"https://hottub.news/stories/citrix-netscaler-rce-zero-days-exploited-globally-for-weeks-cve-2026-iypv2l44su","count":4,"items":[{"id":"n_socnctpbzjz47tfxvq2a","seq":705116,"kind":"article","title":"NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)","url":"https://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771","summary":"The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become widespread “spray and pray” exploitation, fueled by the publication of a root-cause analysis and a proof-of-concept exploit for CVE-2026-88771, which is remotely exploitable on unpatched devices with the default configuration. From rumor to confirmed zero-day Rumors about a NetScaler zero-day being…","published":"2026-09-29T14:59:06Z","seen":"2026-09-29T15:20:32Z","lang":"en","source":{"id":"kite-helpnetsecurity-com-446aa2","name":"helpnetsecurity.com","domain":"helpnetsecurity.com","outlet":{"wikidata":"Q69033353","name":"Help Net Security","type":"website","country":"HR","designations":["website"]}},"via":"kite-helpnetsecurity-com-446aa2","topics":["cybersecurity","don't miss","hot stuff","news","censys","cert-eu","greynoise","lupovis"],"authors":["Zeljka Zorz"],"story":"st_iypv2l44sueeyaatxmpq","category":"science-technology","category_p":0.5899999737739563,"sentiment":"negative","tone":-0.7799999713897705,"political":0.10999999940395355},{"id":"n_cdkhu42yaqj2cydngbqa","seq":470249,"kind":"article","title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild","url":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited","summary":"Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42 .","published":"2026-09-28T15:02:04Z","seen":"2026-09-28T16:15:30Z","lang":"en","source":{"id":"kite-feedburner-com-33cb78","name":"feedburner.com","domain":"feeds.feedburner.com"},"via":"kite-feedburner-com-33cb78","topics":["cybersecurity","high profile threats","vulnerabilities","citrix netscaler","denial of service","remote code execution","zero-day"],"authors":["Unit 42"],"entities":[{"id":"Q12040775","name":"Citrix ADC","type":"org"}],"image":"https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/06_Vulnerabilities_1920x900-5.jpg","story":"st_iypv2l44sueeyaatxmpq","category":"science-technology","category_p":0.5099999904632568,"sentiment":"negative","tone":-0.5899999737739563,"political":0.05999999865889549},{"id":"n_vskqroizz6wsm7ljzlrq","seq":404838,"kind":"article","title":"Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772","url":"https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772","summary":"Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure . CVE-2026-88771 affects vulnerable NetScaler deployments in their…","published":"2026-09-28T10:05:00Z","seen":"2026-09-28T10:48:06Z","lang":"en","source":{"id":"kite-rapid7-com-268062","name":"rapid7.com","domain":"rapid7.com","outlet":{"wikidata":"Q85874460","name":"Rapid7","type":"other","country":"US","designations":["business","public company"]}},"via":"kite-rapid7-com-268062","topics":["cybersecurity","vulnerability management","zero-day","emergent threat response","emerging threats"],"authors":["Rapid7"],"image":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","story":"st_iypv2l44sueeyaatxmpq","category":"science-technology","category_p":0.7799999713897705,"sentiment":"neutral","tone":-0.41999998688697815,"political":0.10999999940395355},{"id":"n_iypv2l44sueeyaatxmpq","seq":406431,"kind":"article","title":"Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)","url":"https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772","summary":"Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited in zero-day attacks to plant webshells on compromised devices. Rumors about their existence and active exploitation popped up on Reddit on Friday, fueled by warnings from IT suppliers, who apparently got the information from the Dutch National Cyber Security Center (NCSC-NL). According to security…","published":"2026-09-28T09:51:32Z","seen":"2026-09-28T10:48:32Z","lang":"en","source":{"id":"kite-helpnetsecurity-com-446aa2","name":"helpnetsecurity.com","domain":"helpnetsecurity.com","outlet":{"wikidata":"Q69033353","name":"Help Net Security","type":"website","country":"HR","designations":["website"]}},"via":"kite-helpnetsecurity-com-446aa2","topics":["cybersecurity","don't miss","hot stuff","news","cisa","citrix","ncsc-nl","netscaler"],"authors":["Zeljka Zorz"],"story":"st_iypv2l44sueeyaatxmpq","category":"science-technology","category_p":0.6299999952316284,"sentiment":"negative","tone":-0.4699999988079071,"political":0.07000000029802322}]}