Image: tenable.com · rights & removal
Frequently asked questions about reported Citrix NetScaler zero
Reporting by Tenable BlogRead the original at tenable.com
Executive Summary
Facts Only
* Two zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were confirmed in Citrix NetScaler ADC and Gateway.
* CVE-2026-88771 is an Improper Input Validation vulnerability with a CVSSv4 score of 9.5.
* CVE-2026-88772 is a Memory Overflow vulnerability with a CVSSv4 score of 9.5, exploitable via malformed DTLS traffic to gain root-level access.
* CVE-2026-88779 is a Memory Overflow vulnerability causing denial of service in SAML deployments, with a CVSSv4 score of 8.7.
* Patches for CVE-2026-88771 and CVE-2026-88772 were released on September 27, 2026.
* A security bulletin (CTX697096) was published on September 27, 2026, confirming the zero-days and releasing patches.
* CVE-2026-88779 affects NetScaler deployments configured for SAML as an SP or IdP.
* Exploitation of CVE-2026-88772 began no later than early September, based on Mandiant and GTIG findings.
* Affected products include NetScaler ADC and NetScaler Gateway across various branches (14.1, 13.1).
* Mitigation for CVE-2026-88772 suggests blocking inbound UDP port 443 or disabling DTLS on affected gateways.
Full Take
From the original · Tenable Blog
day vulnerabilities CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Read the full story at tenable.com
Sentinel — Human
This text reads like a highly synthesized forensic report drawing heavily on external threat intelligence sources to detail specific vulnerability exploitation events rather than a generalized news article.
