Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix confirms two NetScaler RCE zero-days exploited in attacks, releasing patches.
Summary
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are actively being exploited in the wild as zero-days. These vulnerabilities, affecting NetScaler ADC and Gateway appliances, allow unauthenticated attackers to execute arbitrary commands or cause denial-of-service conditions. Citrix has released security updates to address these flaws, which were privately warned about by researchers and agencies before public disclosure.
Full text
Citrix confirms two NetScaler RCE zero-days exploited in attacks By Lawrence Abrams September 27, 2026 12:02 PM 0 Update: Article rewritten with official confirmation from Citrix. Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend. NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks. Compromising one of these devices can give attackers an initial foothold at the perimeter of a victim's network and potentially provide a path to internal systems without first compromising an endpoint inside the organization. The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances. "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote. Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue. Cybersecurity firm watchTowr later publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "authoratitive sources." "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible," watchTowr said. Citrix confirms active exploitation Citrix has now published security bulletin CTX697096, confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances. CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation, allowing an unauthenticated attacker to execute arbitrary commands. It has a severity score of 9.5. Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also with a severity score of 9.5. This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway. Citrix notes that DTLS is enabled by default on VPN virtual servers. Citrix has confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days. "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in the security bulletin. Citrix says the following versions are affected: NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23 NetScaler ADC FIPS before 14.1-73.37 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.279 Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds. Citrix says the bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication. The security bulletin also fixes six other NetScaler vulnerabilities, bringing the total to eight flaws fixed in this update. NCSC warned organizations before disclosure Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days. Multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution. According to the notice, one vulnerability allowed attackers to place shellcode directly into memory, while technical details about the second vulnerability were still being researched. At the time, no CVE identifiers had been assigned, and Citrix had not yet published an advisory. The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation. It also said Citrix submitted a notification under the European Union's Cyber Resilience Act after discovering the attacks. The NCSC said exploitation had been identified at multiple Citrix customers worldwide, although it did not know whether the attacks were widespread. The agency also warned that exploitation attempts could increase once Citrix released patches and additional technical details. Because NetScaler upgrades can cause downtime, the NCSC said the warning was intended to give organizations time to prepare, implement safeguards where possible, and install patches quickly once they became available. BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate. The agency declined to confirm the notification, saying it could not provide further information to organizations outside its constituency. "As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7," the NCSC-NL told BleepingComputer. "We provide information and advice to organizations so that they can take appropriate measures. As you're not part of our constituency, we cannot disclose any further information at this time." Now that Citrix has released fixes and confirmed exploitation, administrators should upgrade affected NetScaler ADC and NetScaler Gateway appliances to the patched versions as soon as possible. Organizations that cannot apply the updates immediately should reduce Internet exposure where operationally possible until they can patch the appliances. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: CISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayF5 patches BIG-IP APM zero-day flaw exploited in RCE attacksN-able patches max severity N-central flaw amid ongoing attacksCritical Citrix NetScaler auth bypass now leveraged in attacksSonicWall warns of actively exploited SMA1000 zero-day flaws
Indicators of Compromise
- cve — CVE-2026-88771
- cve — CVE-2026-88772