Citrix confirmed CVE-2026-88779, a third exploited NetScaler zero-day, after appliances patched against the previous two began rebooting under attack. The vendor rates it denial of service, though logged payloads and a researcher's honeypot point toward code execution.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−10
- Incentives
- Insufficient
- Confidence50
Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.
Perspective Coverage
21 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence88
- Adoption82
- Hype gap−8
- Incentives60
- Confidence86
Citrix has patched eight NetScaler flaws, including two zero-days scored 9.5 that CISA says attackers are exploiting globally. The safest response costs a planned outage of remote access now and months of monitoring afterwards.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
Exposure to CVE-2026-19490, a CVSS 9.8 NetScaler bypass CISA lists as exploited, depends on each appliance's exact build and SAML setup. Older builds qualify with any Gateway or AAA virtual server, while later builds short of the fix also need a SAML action configured.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence55
Citrix has fixed two NetScaler ADC and Gateway flaws, each rated 9.5 out of 10, that attackers were exploiting before any patch existed. CISA wants owners to look for signs of compromise first because the update can erase the evidence, so the upgrade comes second.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
watchTowr says attackers exploited CVE-2026-88771, a pre-auth command injection in default-config Citrix NetScaler, before any fix existed. Upgrading to 14.1-73.37 or 13.1-64.23 closes the hole, though a gateway exposed in that window may already have been used.
Publishers:labs.watchtowr.com
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.
Publishers:dev.to · thestack.technology · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 68%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence72
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.
Perspective Coverage
5 publishers
- Builder
- Builder 14%
- Operator
- Operator 73%
- Investor
- Investor 13%
Reality
- Evidence78
- Adoption62
- Hype gap+10
- Incentives38
- Confidence75
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74