EDGE / ACTIVE EXPLOITATION
27 September · updated 2 October
CVE-2026-88771
CVE-2026-88772
Citrix NetScaler: preserve evidence while closing exposure
CISA's NetScaler alert describes eight disclosed vulnerabilities, but specifically confirms active global exploitation of CVE-2026-88771 and CVE-2026-88772. Each can independently enable remote code execution. The 2 October update adds a SIGMA-rule resource. Do not describe all eight as confirmed exploited.
- Identify affected ADC and Gateway instances and consult Citrix's bulletin for the exact configurations and fixed releases.
- Where feasible, check for compromise and preserve logs before updating; coordinate urgent remediation with the incident-response owner so evidence collection does not become an indefinite delay.
- Review CISA's linked SIGMA repository and validate rule applicability against your actual log sources. Patching alone is not proof that an earlier compromise has been removed.