CVE-2026-88771 & CVE-2026-887722: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gateway, both rated 9.5 🔥
Citrix disclosed two exploited vulnerabilities. The first (CVE-2026-88771) allows an unauthenticated attacker to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments. The second (CVE-2026-88772) leads to RCE or DoS. It affects appliances with DTLS enabled. These vulnerabilities are already being actively exploited in the wild, and PoCs exist!
Search at Netlas.io:
👉 Link: https://nt.ls/m5KaR
👉 Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Post #641
93

- ❤ 1
- 🔥 1