What We Know
CVE-2026-88771 and CVE-2026-88772 are Citrix NetScaler vulnerabilities described by security researchers and government advisories as remote-code-execution zero-days exploited in the wild.2Backed by 2 sourceswatchtowr.comunit42.paloaltonetworks.com
Public-sector cybersecurity organizations in the United States, Canada, and the United Kingdom issued alerts about the NetScaler exploitation.1Context from one sourcecisa.gov The disclosures prompted emergency shutdown measures by some organizations.1Context from one sourcelabs.beazley.security NetScaler documentation gives a concrete dashboard workflow: open CVE Detection, select Impacted Instances, and search for CVE-2026-88771.1Context from one sourcedocs.netscaler.com
Source Comparison
Aligned reporting2 corroborates - 3 adds context - 0 conflicts
Corroborates
Adds context
- labs.beazley.security↗The advisory reports that the disclosures prompted emergency shutdowns, adding an operational response detail to the exploitation account.
- cisa.gov↗CISA’s alert independently frames the incident as critical zero-day exploitation affecting NetScaler ADC and Gateway and notes that it is amplifying Citrix’s disclosure.
- docs.netscaler.com↗NetScaler documentation gives a concrete dashboard workflow: open CVE Detection, select Impacted Instances, and search for CVE-2026-88771.