Cybersecurity Research

Two Critical NetScaler Zero-Days Under Active Attack: Patch Now

Unit 42 · 29 Sept 2026
Key Takeaway If your business uses NetScaler devices, patch immediately and check for signs of prior compromise, since updating alone won't remove attackers who got in before the fix.

Citrix and security researchers at Unit 42 have confirmed that two newly disclosed vulnerabilities affecting NetScaler devices, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild. Both flaws carry a near-maximum severity score of 9.5 out of 10, though specific details about how attackers are exploiting them have not yet been released.

According to Palo Alto Networks' Cortex Xpanse scanning data, more than 50,000 internet-facing NetScaler instances were potentially vulnerable as of late September 2026. NetScaler devices are widely used by organisations for application delivery and remote access, meaning a successful compromise could give attackers a foothold into internal networks.

Unit 42 is urging all NetScaler customers to update to the latest patched versions immediately. Importantly, patching alone will not remove access for attackers who may have already established persistence inside a compromised network before the update was applied, so organisations should also review their systems for signs of prior intrusion.

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.