Disclosure summary
CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026. On
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Cyber Exposure Alerts · RSS-94eac028524926d60b6327b845c2eeb7b52
Open original source · Updated Sep 27, 2026
Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- www.tenable.com — Publisher advisory
PUBLISHED 2026-09-27T05:35:21-04:00
MODIFIED 2026-09-27T05:35:21-04:00
INGESTED 2026-10-08T12:05:46-04:00