NEW: Group Profiler — instant APT intel lookup. Try it →

CVE-2026-88771

Reported by 4 distinct sources tracked by ThreatFilter. First reported 2026-09-27 00:00 UTC , most recent 2026-09-28 15:02 UTC.

MEDIUM 9.5 CISA KEV EXPLOITED citrix

Corroboration timeline

Each row is the first time that source reported this CVE, so the lag column shows how long each took relative to the earliest report. Corroboration across distinct sources is a confidence signal that a single advisory cannot give you.

  1. cisa-kev 2026-09-27 00:00 UTC first report

    CVE-2026-88771 — Citrix NetScaler: Citrix NetScaler Improper Input Validation Vulnerability

  2. sophos-news 2026-09-28 00:00 UTC +24h

    Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

  3. rapid7-blog 2026-09-28 10:05 UTC +34h

    Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

  4. unit42 2026-09-28 15:02 UTC +39h

    Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

How this page is built

ThreatFilter ingests 52 public threat-intelligence feeds. A page is published here only when at least 3 distinct sources report the same CVE — roughly 0.2% of the CVEs seen. Everything above is derived from those feeds; nothing is hand-written, and the timeline is the raw record of what each source published and when.

See the live advisory feed, the full source list, or the analyst tools.