Vulnerabilities

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Citrix vulnerability

Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.

The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.

The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5.

CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration.

CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.

Citrix has made available indicators of compromise (IoCs).

Advertisement. Scroll to continue reading.

Over the weekend, NetScaler administrators said on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why. 

Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions. 

According to a copy posted in the Reddit thread, NCSC-NL said it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. Several admins took their NetScalers offline, while others said they had received no official notice.

CISA rushed to add CVE-2026-88771 and CVE-2026-88772 to its KEV catalog. The agency also issued an alert, warning that “threat actors are actively exploiting these vulnerabilities globally.”

“Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching,” CISA said.

CISA’s KEV catalog currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added CVE-2026-19490 and CVE-2026-8452.

Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Related Content

Cybercrime

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Malware & Threats

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Artificial Intelligence

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Email Security

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Vulnerabilities

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

Vulnerabilities

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

Vulnerabilities

The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version