By David Jones
Publication Date: 2026-09-28 11:20:00
The Cybersecurity and Infrastructure Security Agency on Sunday warned that critical zero-day vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway are facing exploitation and need to be immediately addressed.
Citrix said the exploitation is linked to a remote code execution (RCE) vulnerability due to improper input validation, tracked as CVE-2026-88771, and a memory overflow vulnerability, tracked as CVE-2026-88772.
On Saturday, security teams reported receiving urgent phone calls from IT security firms and other officials warning them to immediately disconnect their servers as the zero-day flaws were being exploited prior to any public guidance from Citrix or government authorities.
Benjamin Harris, president of exposure management specialist watchTowr, confirmed at least one unpatched remote code execution vulnerability was under exploitation as of Saturday. Researchers said the team at the National…



