
Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching
Citrix NetScaler appliances are facing active exploitation of critical zero-day vulnerabilities, specifically CVE-2026-88771, which allows unauthenticated remote code execution on default configurations. The flaw stems from improper input validation in a Perl script used for log analysis, enabling attackers to inject commands via crafted HTTP requests. While Citrix released patches for eight total vulnerabilities, the delay in official disclosure allowed threat actors to exploit the flaw in the wild before government agencies intervened. CISA has now mandated that U.S. federal agencies patch these systems by September 30, while Dutch hospitals have already restricted patient access to mitigate risks. The incident highlights a recurring pattern of Citrix NetScaler vulnerabilities being exploited before official advisories are published, prompting security firms to urge immediate isolation of affected devices.
