Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in real attacks
What happened
Citrix reports that CVE-2026-88771 (the public catalogue number for a specific software flaw) and CVE-2026-88772 have been exploited in the wild. Unit 42 is aware of possible 0-day activity against NetScaler devices.
No further details are currently available about the exploit activity. The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk. They should be seen as general hunting guidance until more is known about the exploitation activity identified by Citrix in their advisory.
Key facts
- Citrix โ reports: that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild
Sources & evidence
- Palo Alto Networks Unit 42 Primary / official
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild โ
https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/