ConciseSignal

Critical zero-days in Citrix NetScaler exploited, patches released

Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited. Both flaws allow remote code execution, and security agencies in the US, UK, and elsewhere have issued urgent patch directives. Citrix released fixes after reports of active exploitation circulated for two days. Over 50,000 instances may be at risk, according to Unit 42. Cybersecurity authorities warn that forensic review and prompt updates are essential.

Why it mattersNetScaler appliances control high-value network access in large organizations, making these flaws a significant entry point for attackers. Late disclosure left defenders exposed to possible compromise before patches became available.

Sources covering this

The Hacker NewsWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation7:47 AM →Unit 42PrimaryThreat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild3:02 PM →TechRadarCitrix says two worrying NetScaler RCE zero-days exploited in attacks3:10 PM →The RecordUS, UK warn of exploited Citrix NetScaler zero-day bugs4:19 PM →CyberScoopCitrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings12:58 AM →

How it unfolded

  • The Hacker News Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
  • Unit 42 Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
  • TechRadar Citrix says two worrying NetScaler RCE zero-days exploited in attacks
  • The Record US, UK warn of exploited Citrix NetScaler zero-day bugs
  • CyberScoop Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
Concise Signal DailyEverything that mattered, every weekday at 7am.

More in Cybersecurity

2 sources · 48m ago

Apple fixes CoreGraphics flaw after targeted attacks

Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly sophisticated attacks targeting specific users of older software versions. The flaw allowed attackers to run code by sending a maliciously crafted file. Apple says improved bounds checking now addresses the issue but hasn't disclosed how many people were targeted or if attacks succeeded.

2 sources · 48m ago

Carbonato botnet uses AI agent to control Docker hosts

Researchers have uncovered that the Carbonato botnet is exploiting unsecured Docker hosts to install the Hermes AI agent, which is controlled by attackers via Telegram. The malware uses a privileged container to obtain persistence, collect credentials, and spread to other servers on local networks. The AI agent receives instructions from operators to perform tasks on the compromised machines and forwards results back over Telegram.

2 sources · 48m ago

Bitget resumes withdrawals after $388M crypto theft

Bitget has resumed Bitcoin withdrawals after attackers stole around $388 million from its hot and warm wallets by exploiting a third-party security product vulnerability. The theft, detected on September 24, did not affect Bitget's cold wallets or user accounts. Bitget says the exploited weakness has been fixed, and withdrawals for other cryptocurrencies will follow. The incident remains under investigation with outside experts assisting.

2 sources · 47m ago

Federal judge halts Utah's VPN age-check law

A federal judge has temporarily stopped enforcement of Utah's new law requiring adult websites to verify users' physical locations, even if they're using VPNs. The ruling came after Aylo, Pornhub's parent company, challenged the law, arguing it was unconstitutional. The court found it likely violates the U.S. Constitution, particularly the dormant Commerce Clause. The law would have forced sites to bypass VPN encryption and verify all users' locations, a technical impossibility according to the judge.