Citrix Patches Two Actively Exploited NetScaler Zero-Days Rated CVSS 9.5

Citrix released advisory CTX697096 on September 27, 2026, fixing eight vulnerabilities in NetScaler ADC and Gateway, including two critical zero-days already being exploited in the wild. Security firm watchTowr had issued a public warning a day earlier, citing findings from a forensic investigation, while the Dutch national cybersecurity center privately advised some organizations to take affected appliances offline. Both zero-days — CVE-2026-88771 and CVE-2026-88772 — carry a CVSS v4 score of 9.5 and allow unauthenticated remote code execution on default configurations. CISA added both flaws to its Known Exploited Vulnerabilities catalog the same day, giving federal agencies only until September 30 to apply patches. Separately, Sidero Labs announced on September 14 that Talos Linux would gain native hypervisor capabilities, enabling unified management of containers and virtual machines through a single OS and API, with general availability targeted for December 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in