LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
cve recordhighexploited in the wildzero day3 of 3 cataloguesexploit reported

CVE-2026-88772

Citrix · NetScaler · Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

· Added to CISA KEV
CVSS—
Severityhigh
Weakness—
EPSS1.3%69.5th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueSep 30, 2026
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE reserved
  2. CVE published17d
  3. First KEV listingsame day
  4. Last sightingsame day

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by0 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

1 public report collected from VulnCheck and CIRCL, first on Sep 27, 2026. Each links to its original source. We have not verified them.

Description

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-88772

CVE-2026-88771critical

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

CVE-2026-88771

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Reports indicate that government and finance organizations have been targeted in weeks-long attacks exploiting zero-day vulnerabilities in NetScaler products. The attacks leverage two specific vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, with multiple security firms confirming observed exploitation.

CVE-2026-88772

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both…

CVE-2026-88771critical

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

CVE-2026-88771critical

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…