# Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

DevFeed: [Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild](<https://devfeed.tech/articles/threat-brief-netscaler-zero-days-cve-2026-88771-and-cve-2026-88772-exploited-in-the-wild-61383.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/>)

Author: Unit 42

Published: 2026-09-28T15:02:04Z

Content type: news

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [known exploitable vulnerabilities](<https://devfeed.tech/topics/known-exploitable-vulnerabilities.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>)

Tags: [citrix](<https://devfeed.tech/tags/citrix.md>), [citrix-netscaler](<https://devfeed.tech/tags/citrix-netscaler.md>), [cve-2026-88771](<https://devfeed.tech/tags/cve-2026-88771.md>), [cve-2026-88772](<https://devfeed.tech/tags/cve-2026-88772.md>), [cvss-v4-0](<https://devfeed.tech/tags/cvss-v4-0.md>), [denial-of-service](<https://devfeed.tech/tags/denial-of-service.md>), [high-profile-threats](<https://devfeed.tech/tags/high-profile-threats.md>), [netscaler](<https://devfeed.tech/tags/netscaler.md>), [patch](<https://devfeed.tech/tags/patch.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

## AI overview

Unit 42 reports that Citrix says two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have been exploited in the wild. The article describes remote code execution and denial-of-service risks, notes more than 50,277 potentially exposed instances in Palo Alto Networks telemetry as of September 27, 2026, and recommends updating affected software, checking exposure, isolating vulnerable systems, preserving evidence, and hunting for suspicious activity.

## Source excerpt

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.