Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days

3 min read
Source: The Hacker News
Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days
Photo: The Hacker News
TL;DR

Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.

Key points

  • CVE-2026-88771 allows unauthenticated attackers to execute arbitrary commands via improper input validation, affecting all NetScaler deployments.
  • CVE-2026-88772 is a memory overflow flaw that enables RCE or denial-of-service, impacting appliances with DTLS enabled, a default setting for VPN virtual servers.
  • Citrix released fixes in versions 14.1-73.37 and 13.1-64.23, noting that the 13.1 branch had recently reached End of Maintenance.
  • The bulletin includes six other high-severity flaws, such as HTTP request smuggling and memory overflows, but only the two RCE issues are confirmed exploited.
  • Citrix provided no indicators of compromise or workarounds, advising users to preserve evidence and isolate compromised appliances immediately.

Background

This incident follows a pattern of critical NetScaler vulnerabilities in 2026, including an authentication bypass (CVE-2026-19490) patched in August. In 2025, a similar zero-day against Dutch organizations led to warnings that patching alone might not remove attacker access. The current situation mirrors that risk, as exploitation occurred before public disclosure, meaning some systems may already be compromised despite recent updates.

How outlets are covering it

The Hacker News and BleepingComputer emphasize the confirmed active exploitation and the lack of indicators of compromise, highlighting the urgency of patching. Cyber Kendra and heise online focus on the pre-disclosure chaos, noting that Dutch NCSC and watchTowr warned organizations before Citrix acted. While heise online notes that no government agencies like CISA or BSI had issued public warnings at the time of their initial report, BleepingComputer details that the Dutch NCSC sent pre-notifications to its constituency. All sources agree that the flaws are distinct from the August authentication bypass, though some initial confusion existed among administrators.

Why it matters

NetScaler appliances are critical edge devices for VPN and authentication. Unpatched RCE vulnerabilities provide attackers with a direct foothold into enterprise networks. The lack of indicators of compromise means organizations cannot easily verify if they have been breached, making immediate patching and forensic checks essential to prevent lateral movement and data theft.

What to watch

Administrators must immediately upgrade to the patched versions (14.1-73.37 or 13.1-64.23). Those unable to patch should restrict internet exposure and monitor for anomalies. Citrix advises preserving evidence and isolating suspected compromised devices. Organizations should also review logs for signs of prior intrusion, as patching does not guarantee removal of existing attacker access.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News