US, UK warn of exploited Citrix NetScaler zero-day bugs
Agencies warn exploited Citrix NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 require immediate patching and forensic triage.
US, UK, and Dutch agencies warned that Citrix NetScaler ADC and Gateway zero-days are under active exploitation. Citrix confirmed eight new vulnerabilities; CVE-2026-88771 and CVE-2026-88772, both scored 9.5, have been exploited, and patches are available. CISA ordered US federal agencies to patch the two exploited bugs by Wednesday and to perform forensic triage, citing intelligence of global exploitation. watchTowr said CVE-2026-88771 was exploited before a fix existed and released a susceptibility-check tool.
- Eight new NetScaler bugs; CVE-2026-88771 and CVE-2026-88772 are exploited and scored 9.5.
- CISA set a Wednesday federal patch deadline and mandated forensic triage.
- Citrix, CISA, and UK and Dutch agencies issued weekend warnings.
- watchTowr says CVE-2026-88771 was hit before a patch and shipped a check tool.
- NetScaler appliances are widely deployed enterprise VPN and traffic gateways.
Vulnerabilities mentionedAll →
- CVE-2026-887729.51%Unauthenticated RCE/DoS in Citrix NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC KEV PoC ×2+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article355 words · extracted from therecord.media · click to collapse
Several governments sent out urgent warnings this weekend about zero-day vulnerabilities impacting Citrix NetScaler application delivery controllers (ADC) and Gateway devices, which serve as front doors for users connecting to an organization’s environment. Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities. Of the eight, CVE-2026-88771 and CVE-2026-88772 have been exploited, according to Citrix. Both carry severity scores of 9.5 out of 10 and patches have been released for all of the bugs. The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal agencies until Wednesday to patch the two exploited vulnerabilities and said “forensic triage” will need to be conducted at any agency using the products. “CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said. “Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories.” The tools are used by large organizations to manage traffic and authentication. Citrix provided detailed guidance on what customers should do if they suspect they have been compromised through any of the bugs. The incident caused alarm online because several private security companies urged customers to take their NetScaler appliances offline on Saturday without providing any evidence of vulnerabilities. Some reported exploitation of the bugs dating back to last Thursday. CVE-2026-88771 was exploited before any fix existed, according to cybersecurity researchers at watchTowr, which provided a tool that allows organizations to determine how susceptible they are to the bug. Citrix NetScaler appliances are frequent targets for hackers because of their centrality and popularity. WatchTowr explained that Citrix NetScaler is a “family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.” High-profile hacking campaigns targeting the products — colloquially known as Citrix Bleed One and Two — led to hundreds of breaches and another Citrix NetScaler ADC bug emerged in March.