www.darkreading.com 2 Oct 2026, 16:56 UTC

Citrix NetScaler Zero Days Exploited as Vendors Take Different Risks

Citrix NetScaler Zero Days Exploited as Vendors Take Different Risks
CyberSIXT Evidence Panel Source marked as original reporting

THREAT researchers tracked a sequence of zero-day events around Citrix NetScaler over the weekend of 24–26 September. GreyNoise Intelligence observed a US-based IP address scanning NetScaler installations and attempting remote code execution, with social media chatter about zero-day attacks in the days that followed.

Citrix moved to patch eight vulnerabilities (CVE-2026-88771 through CVE-2026-88778) in a post dated 26 September, noting that two of the zero-days (CVE-2026-88771 and CVE-2026-88772) had been exploited in the wild. The company urged customers to upgrade to the fixed versions immediately, while information about who was affected and how extensively the exploitation occurred remained mixed. Shadowserver data highlighted that affected IPs were worldwide, though clustering in the United States and Europe.

In parallel, Kiteworks took a markedly different approach. On 25 September the data-protection specialist urged customers to take their systems offline in light of intelligence about an imminent zero-day attack, even before a patch was released. An advisory on 26 September documented a patch, but Kiteworks later said the vulnerability would affect only about 1% of its customers.

The two responses illustrate divergent risk appetites: Citrix faced scrutiny for a more reactive stance amid active exploitation, while Kiteworks’ proactive shutdown guidance drew both praise and criticism. Industry perspectives varied on whether shutting down briefly was prudent given the broad potential impact and the patch deployment burden. Citrix later reaffirmed its push to upgrade promptly, whereas Kiteworks defended its cautious, data-driven decision.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline