PALO Alto Networks’ Unit 42 has warned of possible zero-day activity targeting Citrix NetScaler appliances. Citrix reports that CVE-2026-88771 and CVE-2026-88772 have been exploited in the wild, although no further details about the attacks are currently available. CVE-2026-88771 is an input-validation flaw that allows an unauthenticated attacker to execute commands remotely on NetScaler ADC and NetScaler Gateway systems.
CVE-2026-88772 is a memory-overflow vulnerability affecting the Datagram Transport Layer Security (DTLS) configuration and could enable remote code execution or denial of service. Both have a CVSS v4.0 base score of 9.5.
Unit 42 advises customers to update Citrix software to the latest versions urgently and use Citrix’s advisory to check whether appliances meet the vulnerabilities’ preconditions. It also recommends isolating vulnerable systems, preserving appliance snapshots, logs, technical support bundles and packet-engine core dumps, and looking for suspicious administrative sessions, unexpected outbound connections and unexplained logging gaps.
The company stresses that these are general hunting suggestions, not attack techniques observed specifically in connection with the flaws, and that patching will not remove persistence established by an attacker. As of 27 September 2026, Cortex Xpanse telemetry identified more than 50,277 potentially vulnerable exposed instances.