CYBERSECURITYTRACKER
TRACKING
Permanent story citation

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8882

As cited

Copy frozen at (site build).

vulnerabilities

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

Citrix NetScaler ADC and Gateway deployments face escalating exploitation of CVE-2026-88771, a remote code execution vulnerability affecting unpatched devices with default configurations. Mass attacks have intensified following the public release of a root-cause analysis and proof-of-concept exploit, shifting from targeted zero-day attacks to widespread opportunistic compromise.

Why it matters: Organizations running internet-exposed NetScaler instances must apply patches immediately; this vulnerability is actively exploited at scale and requires no authentication on default configurations.

VendorsCitrixGoogleLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

Citrix NetScaler ADC and Gateway deployments face escalating exploitation of CVE-2026-88771, a remote code execution vulnerability affecting unpatched devices with default configurations. Mass attacks have intensified following the public release of a root-cause analysis and proof-of-concept exploit, shifting from targeted zero-day attacks to widespread opportunistic compromise.

Why it matters: Organizations running internet-exposed NetScaler instances must apply patches immediately; this vulnerability is actively exploited at scale and requires no authentication on default configurations.

VendorsCitrixGoogleLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary