Back to Feed
Zero-daySep 28, 2026

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix patches two NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) being actively exploited in the wild.

Summary

Citrix released emergency patches for two critical NetScaler zero-day vulnerabilities (CVSS 9.5) that are actively being exploited globally. CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow affecting appliances with DTLS enabled. The Dutch NCSC-NL pre-notified European CERTs under TLP:AMBER, prompting administrators to take appliances offline before official disclosure; CISA subsequently added both CVEs to its Known Exploited Vulnerabilities catalog.

Full text

Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild. The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues. The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5. CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration. CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers. Citrix has made available indicators of compromise (IoCs).Advertisement. Scroll to continue reading. Over the weekend, NetScaler administrators said on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why. Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions. According to a copy posted in the Reddit thread, NCSC-NL said it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. Several admins took their NetScalers offline, while others said they had received no official notice. CISA rushed to add CVE-2026-88771 and CVE-2026-88772 to its KEV catalog. The agency also issued an alert, warning that “threat actors are actively exploiting these vulnerabilities globally.” “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching,” CISA said. CISA’s KEV catalog currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added CVE-2026-19490 and CVE-2026-8452. Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Windows, Linux, Android File Notification Systems Leak User ActivityOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsUS Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity Latest News Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksChina and US Agree to Establish AI Safety Channel and Continue Trade and Military TalksNew x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingOpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior DisclosureIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureNorth Korea Suspected in $351 Million Bitget Crypto HeistCISA Election Security Plan Flags Patching Barriers, Voter Database AttacksKosovar Owner of Rydox Marketplace Pleads Guilty in US Court Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-88771
  • cve — CVE-2026-88772
  • cve — CVE-2026-19490
  • cve — CVE-2026-8452

Entities

Citrix (vendor)NetScaler ADC (product)NetScaler Gateway (product)CISA (vendor)