CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution.
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
About this summary. This is a short, independently written summary of an article first published by CISA. Cyber Security News did not report or verify the underlying story. Read the original: https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
Source attribution: headline and facts are from CISA (cisa.gov). Summary method: excerpt of the source description. See our source attribution policy.




