Tag

Zero Day Exploitation

All articles tagged with #zero day exploitation

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching
cybersecurity12 days ago

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching

Citrix NetScaler appliances are facing active exploitation of critical zero-day vulnerabilities, specifically CVE-2026-88771, which allows unauthenticated remote code execution on default configurations. The flaw stems from improper input validation in a Perl script used for log analysis, enabling attackers to inject commands via crafted HTTP requests. While Citrix released patches for eight total vulnerabilities, the delay in official disclosure allowed threat actors to exploit the flaw in the wild before government agencies intervened. CISA has now mandated that U.S. federal agencies patch these systems by September 30, while Dutch hospitals have already restricted patient access to mitigate risks. The incident highlights a recurring pattern of Citrix NetScaler vulnerabilities being exploited before official advisories are published, prompting security firms to urge immediate isolation of affected devices.

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days
security12 days ago

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days

Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.