Citrix Patches Two NetScaler Zero-Days Already Under Active Attack

Citrix on September 27, 2026, disclosed two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances that attackers were already exploiting before patches were released. The US Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its Known Exploited Vulnerabilities catalog the same day, according to Rapid7 and Cybersecurity Dive.

The two critical flaws

The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, and both carry a CVSS score of 9.5, according to The Hacker News and Rapid7.

CVE-2026-88771 is an improper input validation bug that lets an attacker without credentials run commands on the device. Rapid7 noted that it affects vulnerable NetScaler deployments in their default configuration, with no additional product features required.

CVE-2026-88772 is a memory overflow flaw that can lead to remote code execution or denial of service. It affects appliances with DTLS enabled, which The Hacker News noted is on by default for VPN virtual servers. Rapid7 rated it as harder to exploit than the first flaw.

Citrix confirmed that both bugs had been exploited on unmitigated NetScaler deployments, according to The Hacker News. The same security bulletin covered six more flaws, CVE-2026-88773 through CVE-2026-88778, with no evidence of exploitation.

Attacks before the fix

Rapid7 said it observed the earliest exploitation attempts on September 20, 2026, and saw a webshell compromise at a second organization on September 24. In the two compromises it described, attackers used CVE-2026-88771 to target configuration archives containing encrypted credentials and SSL private keys.

Benjamin Harris, founder and CEO of security firm watchTowr, confirmed that "at least one unpatched remote code execution vulnerability was under exploitation" as of Saturday, September 27, Cybersecurity Dive reported. The Shadowserver Foundation counted "more than 20,000 instances" exposed online, though confirmed compromises remain limited, according to the same report.

What administrators need to do

Citrix has released fixed builds. According to The Hacker News and Rapid7, customers should move to NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later, with matching updates for FIPS versions. The Hacker News noted that the 13.1 fix arrived after that branch reached End of Maintenance on September 15. Citrix-managed cloud services are being upgraded by Citrix directly, Cybersecurity Dive reported.

Rapid7 recommends "updating affected NetScaler appliances on an emergency basis, outside of normal patching cycles." The Hacker News reported that Citrix provided no workarounds or indicators of compromise, and advised organizations that suspect a compromise to preserve evidence and to rotate credentials and revoke certificates.

Why it matters

NetScaler appliances sit at the edge of many corporate and government networks, handling remote access and traffic for internal systems. Because the main flaw works on default settings and needs no login, unpatched devices are exposed to anyone who can reach them, and stolen credentials or keys can remain useful to attackers even after a patch is applied.


Sources

This article was drafted with AI assistance and checked against the sources above. Company claims are reported as claims. Cover image is AI-generated.