Skip to main content

Software

Citrix confirms two NetScaler zero-days under active exploitation

Citrix released patches on 27 September after confirming two critical remote code execution flaws exploited in the wild.

Citrix confirms two NetScaler zero-days under active exploitationPhoto: BleepingComputer

Key points

Citrix confirmed two critical NetScaler zero-day vulnerabilities are being exploited in attacks and released security updates to fix the flaws on 27 September 2026.

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities are being exploited in attacks and that it has released security updates to fix the flaws. The company published a security bulletin on 27 September 2026 detailing the active exploitation and providing patches for affected NetScaler ADC and NetScaler Gateway appliances. This confirmation came after cybersecurity researchers and national agencies had privately warned organizations about the vulnerabilities over the weekend prior to the official announcement.

Official confirmation released

The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances. One administrator wrote that their IT supplier security team advised them to shut their Netscalers down immediately without giving details. Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue before any public statement.

Cybersecurity firm watchTowr later publicly warned that it was rapidly reacting to rumors that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with authoritative sources. The firm stated that while details were scarce the information was credible. WatchTowr founder Benjamin Harris advised affected users on LinkedIn to disconnect the devices from the network immediately until patches could be applied.

Citrix has now published security bulletin CTX697096 confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances. The bulletin identifies CVE-2026-88771 and CVE-2026-88772 as the specific flaws being exploited. Citrix stated in the bulletin that exploits of these vulnerabilities on unmitigated NetScaler deployments have been observed in the wild targeting customer environments globally.

Technical details disclosed

CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation allowing an unauthenticated attacker to execute arbitrary commands. It has a severity score of 9.5 on the CVSS scale. Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments including those using the default configuration and does not require any additional feature to be enabled for exploitation to occur.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition also with a severity score of 9.5. This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway. Citrix notes that DTLS is enabled by default on VPN virtual servers which increases the exposure of affected deployments to this specific flaw.

The Dutch National Cyber Security Center reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days before Citrix publicly disclosed the vulnerabilities. Multiple people shared copies of the notification online which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution. The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation.

Pre disclosure warnings

The NCSC said exploitation had been identified at multiple Citrix customers worldwide although it did not know whether the attacks were widespread. The agency also warned that exploitation attempts could increase once Citrix released patches and additional technical details. Because NetScaler upgrades can cause downtime the NCSC said the warning was intended to give organizations time to prepare and implement safeguards where possible before installing patches quickly.

Citrix says the following versions are affected NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23. NetScaler ADC FIPS before 14.1-73.37 FIPS and NetScaler ADC FIPS and NDcPP before 13.1-37.279 are also affected. Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds to address the vulnerabilities.

The security bulletin also fixes six other NetScaler vulnerabilities bringing the total to eight flaws fixed in this update. Citrix says the bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication separately from the on-premise appliance patches provided in the bulletin.

Administrators on Reddit confirmed that the manufacturer had confirmed the flaws on the and that developers were working around the clock on their remediation. British security researcher Kevin Beaumont held the rumors credible and verified the information after checking with sources. He noted that while Citrix did not advise disconnection the devices should be taken offline immediately given the active exploitation in the wild.

Build numbers for the fixes include NetScaler 13.1 version 13.1-64.24 and NetScaler 14.1 version 14.1-73.37. These new versions are listed on the publicly accessible download page for NetScaler though the downloads are only available to customers. Administrators should install the new versions as quickly as possible to prevent exploitation of the zero-day flaws in their environments.

Frequently asked questions

Which NetScaler versions are affected by the zero-day vulnerabilities?

NetScaler ADC and Gateway versions 13.1 before 13.1-64.23 and 14.1 before 14.1-73.37 are affected along with FIPS and NDcPP variants.

When were the security patches released?

Citrix released security updates on 27 September 2026 in security bulletin CTX697096 to fix the exploited vulnerabilities.

What is the severity score of the vulnerabilities?

Both CVE-2026-88771 and CVE-2026-88772 have a CVSS severity score of 9.5 indicating critical risk.

How this story was checked

  • Fact-checked against 3 cited pages. 42 figures, dates and quotations in this story were found on the pages it cites.
  • Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
  • bleepingcomputer.comread and checked
  • thehackernews.comread and checked
  • heise.deread and checked

Written by Kaer from public reporting. Checked 27 September 2026.

3 sources

More from this edition