Citrix NetScaler unauthenticated RCE vulnerability

Citrix NetScaler unauthenticated RCE vulnerability lets attackers run commands with no login. Two zero-days exploited, patch now, CISA deadline Sep 30.

Citrix confirmed on September 27 that a Citrix NetScaler unauthenticated RCE vulnerability, tracked as two separate CVEs, was already being exploited in the wild before any patch existed. CVE-2026-88771 lets an attacker with no credentials run arbitrary commands on any NetScaler ADC or Gateway appliance in a vulnerable version, default configuration included. Its sibling flaw,…

Read More