Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.
The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.
The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5.
CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration.
CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.
Citrix has made available indicators of compromise (IoCs).
Over the weekend, NetScaler administrators said on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why.
Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions.
According to a copy posted in the Reddit thread, NCSC-NL said it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. Several admins took their NetScalers offline, while others said they had received no official notice.
CISA rushed to add CVE-2026-88771 and CVE-2026-88772 to its KEV catalog. The agency also issued an alert, warning that “threat actors are actively exploiting these vulnerabilities globally.”
“Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching,” CISA said.
CISA’s KEV catalog currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added CVE-2026-19490 and CVE-2026-8452.
Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs
