Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days

Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.
Key points
- CVE-2026-88771 allows unauthenticated attackers to execute arbitrary commands via improper input validation, affecting all NetScaler deployments.
- CVE-2026-88772 is a memory overflow flaw that enables RCE or denial-of-service, impacting appliances with DTLS enabled, a default setting for VPN virtual servers.
- Citrix released fixes in versions 14.1-73.37 and 13.1-64.23, noting that the 13.1 branch had recently reached End of Maintenance.
- The bulletin includes six other high-severity flaws, such as HTTP request smuggling and memory overflows, but only the two RCE issues are confirmed exploited.
- Citrix provided no indicators of compromise or workarounds, advising users to preserve evidence and isolate compromised appliances immediately.
Background
This incident follows a pattern of critical NetScaler vulnerabilities in 2026, including an authentication bypass (CVE-2026-19490) patched in August. In 2025, a similar zero-day against Dutch organizations led to warnings that patching alone might not remove attacker access. The current situation mirrors that risk, as exploitation occurred before public disclosure, meaning some systems may already be compromised despite recent updates.
How outlets are covering it
The Hacker News and BleepingComputer emphasize the confirmed active exploitation and the lack of indicators of compromise, highlighting the urgency of patching. Cyber Kendra and heise online focus on the pre-disclosure chaos, noting that Dutch NCSC and watchTowr warned organizations before Citrix acted. While heise online notes that no government agencies like CISA or BSI had issued public warnings at the time of their initial report, BleepingComputer details that the Dutch NCSC sent pre-notifications to its constituency. All sources agree that the flaws are distinct from the August authentication bypass, though some initial confusion existed among administrators.
Why it matters
NetScaler appliances are critical edge devices for VPN and authentication. Unpatched RCE vulnerabilities provide attackers with a direct foothold into enterprise networks. The lack of indicators of compromise means organizations cannot easily verify if they have been breached, making immediate patching and forensic checks essential to prevent lateral movement and data theft.
What to watch
Administrators must immediately upgrade to the patched versions (14.1-73.37 or 13.1-64.23). Those unable to patch should restrict internet exposure and monitor for anomalies. Citrix advises preserving evidence and isolating suspected compromised devices. Organizations should also review logs for signs of prior intrusion, as patching does not guarantee removal of existing attacker access.
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation The Hacker News
- New vulnerabilities in Citrix Netscaler allow for code execution heise online
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days BleepingComputer
- Unpatched NetScaler Zero-Days Exploited, watchTowr Says cyberkendra.com
- NetScaler attacks: Zero days reported exploited thestack.technology
Want the full story? Read the original reporting
Read on The Hacker News