Two Citrix NetScaler Zero-Days Exploited (09/27/2026)
- › Citrix confirmed that CVE-2026-88771 and CVE-2026-88772, both rated 9.5, were exploited in NetScaler ADC and Gateway before fixes were available.
- › CVE-2026-88771 affects every ADC and Gateway deployment on an affected version, with no extra feature required.
- › Fixed builds are 14.1-73.37 and 13.1-64.23 or later, and Citrix shipped fixes for six more flaws at the same time.
- › Patching does not remove an attacker who got in first, so Citrix's own guidance includes evidence preservation and credential rotation.
- › The Lunex stealer platform uses a vulnerable AMD driver to blind endpoint security while leaving it running.
NetScaler sits at the front of the network by design, which is why its bad weekends keep turning into everybody’s bad month. Citrix confirmed on Sunday that two critical flaws were exploited before fixes existed, and the more serious one needs nothing enabled beyond the product itself. The patch arrived with the disclosure, which helps with the next attacker and does nothing about the ones who got in first.
Top Security Alerts
1. Citrix Confirms Two Exploited NetScaler Zero-Days
Citrix confirmed that CVE-2026-88771, an improper input validation flaw giving unauthenticated remote code execution, and CVE-2026-88772, a memory overflow leading to code execution or denial of service, both rated 9.5, were exploited in NetScaler ADC and NetScaler Gateway, per The Hacker News and BleepingComputer. The first affects every ADC and Gateway deployment on an affected version with no extra feature required, and the second affects appliances with DTLS enabled, which is the default for VPN virtual servers. Fixed builds are 14.1-73.37 and later and 13.1-64.23 and later, and Citrix patched six further flaws, CVE-2026-88773 through CVE-2026-88778, at the same time.
Operator Note: Exploitation came before the patch, so installing it answers only half the question. Follow Citrix’s incident guidance to preserve evidence, look for signs of prior access, and rotate credentials that passed through the appliance, because a gateway sees every session that uses it.
2. Lunex Stealer Blinds Endpoint Security With an AMD Driver
Ontinue’s analysis shows the Psychedelic stealer delivered through compromised Ukrainian websites is part of a malware-as-a-service platform called Lunex, which loads a vulnerable AMD Radeon Software kernel driver affected by CVE-2023-20598 to escalate privileges and disable security monitoring while leaving the protective software running, per The Hacker News. The stealer then takes credentials from seven Chromium browsers and targets desktop and extension cryptocurrency wallets. The infection starts with a fake Cloudflare verification page asking the victim to paste a command.
Operator Note: An endpoint agent that reports healthy while blind is worse than one that reports down. Microsoft’s vulnerable driver blocklist exists for this technique, and it is worth confirming it is actually enforced on your fleet.
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.