Citrix Confirms Attackers Exploited Two NetScaler Zero-Days Before a Patch Existed
Citrix says two critical NetScaler flaws were already being exploited, discovered through forensic investigation of compromised customers, before any patch was available.
Citrix has confirmed that two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772, were already being exploited as zero-days: attackers found and used them before Citrix had a patch ready. The company published security bulletin CTX697096 on Sunday, confirming the two flaws alongside six other NetScaler vulnerabilities and shipping fixes for all eight at once.
Table Of Content
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said in the bulletin. The company did not disclose who was behind the attacks, how many organizations were affected, or when the exploitation actually began, according to The Hacker News.
A bug that needs nothing but a network connection
CVE-2026-88771 carries a CVSS v4.0 score of 9.5 and stems from improper input validation (CWE-20) that lets a remote, unauthenticated attacker execute arbitrary commands. Citrix’s bulletin says it affects every NetScaler ADC and NetScaler Gateway deployment, including appliances left at their default configuration, with no additional feature needing to be turned on first.
CVE-2026-88772, also rated 9.5, is a memory overflow bug (CWE-119) that can trigger remote code execution or a denial-of-service condition. It requires DTLS, the UDP-based version of TLS, to be enabled on a virtual server, and Citrix’s bulletin notes that DTLS is turned on by default for VPN virtual servers. That means a typical NetScaler Gateway configured for remote access is exposed unless an administrator has explicitly switched DTLS off.
Both bugs affect NetScaler ADC and Gateway 14.1 before build 14.1-73.37 and 13.1 before build 13.1-64.23, along with the matching FIPS and NDcPP builds. Secure Private Access Hybrid deployments that use NetScaler instances are affected too and need the same upgrade. Citrix says the bulletin covers only customer-managed appliances; Cloud Software Group, Citrix’s parent company, is separately upgrading its own Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Notably, appliances already updated in August for a different, previously exploited NetScaler bug, on builds 14.1-73.32 and 13.1-63.21, still fall inside today’s vulnerable range and need this new patch too, according to Cyber Kendra.
A weekend of shutdown calls before Citrix said a word
The confirmation followed a weekend in which NetScaler administrators were told to act before any vendor or agency said anything in public. On Saturday, September 26, security firm watchTowr posted that it was “rapidly reacting to rumors” of multiple unpatched NetScaler remote code execution flaws circulating in the wild, adding that “while details are scarce, the information is credible.” A follow-up post from watchTowr later that day said the flaws had been discovered during forensic investigations and that Citrix’s own communications and patches were expected early in the week of September 28, according to The Hacker News. Citrix’s bulletin actually arrived a day earlier than that, on Sunday.
Around the same time, administrators began describing the same pattern on Reddit’s r/Citrix: IT suppliers and security teams calling to advise an immediate shutdown of NetScaler appliances, without giving any technical detail. “We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately,” one administrator wrote, and others in the same thread said law enforcement, CERTs, and national cybersecurity agencies had contacted their organizations too, according to BleepingComputer. Where that original warning actually came from has not been established.
The Dutch National Cyber Security Centre (NCSC-NL) sent Netherlands-based organizations a pre-notification before Citrix’s public disclosure, saying it had received information from a European partner CERT about two vulnerabilities that “could independently lead to remote code execution.” According to that notice, one flaw let attackers place shellcode directly into memory, while technical detail on the second was still being worked out, and no CVE identifiers had been assigned yet. The notification said Citrix discovered both vulnerabilities while investigating incidents in customer environments, identified active exploitation, and submitted a notification under the European Union’s Cyber Resilience Act after finding the attacks, according to BleepingComputer. NCSC-NL said exploitation had already been identified at multiple Citrix customers worldwide, though it did not know whether the attacks were widespread, and it followed up with a formal advisory Sunday evening urging organizations to patch immediately.
Found through forensics, not disclosed by a researcher
The sequence points to something more specific than a typical find-it-then-fix-it disclosure. Citrix appears to have identified both zero-days while investigating incidents at customers who were already compromised, rather than receiving a report from an outside researcher ahead of any attack. The bulletin’s acknowledgements section credits Michael Tucker, Chew Keong Tan, and Alex Bernier of JPMorgan Chase’s XOR Team, along with independent researcher Maxim Suhanov, for “working with us to protect our customers,” but Citrix does not attribute individual credit to either of the two exploited bugs specifically. Because both flaws were being actively exploited before any fix was public, installing the update alone will not reveal whether an attacker already got in first, and Citrix’s own existing guidance for a suspected NetScaler compromise begins by telling administrators to preserve forensic evidence before doing anything else, according to The Hacker News.
Six more bugs, none reported as exploited yet
The same bulletin fixes six additional vulnerabilities that Citrix does not currently list as exploited. CVE-2026-88773, an HTTP request smuggling flaw that Citrix says it found internally, carries a CVSS score of 9.3 and affects appliances with load balancing, content switching, VPN, or authentication virtual servers of type HTTP or SSL. CVE-2026-88774, rated 7.0, is a policy bypass affecting configurations that use an HTTP URL-based policy expression. Three memory overflow bugs, CVE-2026-88775, CVE-2026-88776, and CVE-2026-88777, each rated 8.8, can cause erratic behavior or a denial of service on Gateway or AAA virtual servers, Oracle-type load balancing virtual servers, and load balancing or CGNAT setups using non-HTTP Layer 7 features, respectively. The last, CVE-2026-88778, also rated 8.8, is a TCP Initial Sequence Number prediction flaw; unlike the other seven, fixing it requires an additional manual configuration change (enabling Enhanced ISN Generation) on top of the version upgrade, not the upgrade by itself.
Not yet on CISA’s radar
As of publication, neither CVE-2026-88771 nor CVE-2026-88772 appears in the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, which was last updated September 25, two days before Citrix’s disclosure. That is likely to change: CISA has consistently added actively exploited Citrix bugs to the catalog once exploitation is confirmed, and it added the authentication bypass Citrix patched in August, CVE-2026-19490, to the catalog with a three-day federal patch deadline just over two weeks ago, as sxz.io reported at the time.
NetScaler appliances sit at the edge of enterprise networks, where they typically handle VPN access, load balancing, and authentication for everything behind them, which is part of why Citrix flaws draw fast, serious attention from attackers once details become public. Organizations running customer-managed NetScaler ADC or NetScaler Gateway appliances should treat this as an emergency patch: upgrade to 14.1-73.37, 13.1-64.23, or the matching FIPS and NDcPP builds immediately, check whether DTLS is enabled on any VPN or Gateway virtual server (it is, by default, unless explicitly turned off), and preserve logs before assuming a clean patch means a clean appliance. Citrix’s bulletin lists no workaround and no published indicators of compromise for either of the two exploited flaws, so the version upgrade is the only mitigation currently available.








No Comment! Be the first one.