Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix patched two actively exploited NetScaler zero-days (CVE-2026-88771/88772, CVSS 9.5); CISA added both to KEV amid global attacks.
Citrix rushed out weekend patches for eight NetScaler ADC and NetScaler Gateway vulnerabilities, including two zero-days confirmed exploited in the wild: CVE-2026-88771, an unauthenticated remote code execution flaw affecting all ADC/Gateway deployments including default configuration, and CVE-2026-88772, a memory overflow enabling RCE or DoS on DTLS-enabled appliances (default on VPN virtual servers), both CVSS 9.5. CISA added both CVEs to its KEV catalog and issued an alert warning that threat actors are actively exploiting them globally. A private TLP:AMBER NCSC-NL notification, sourced from a European partner CERT, reported exploitation at multiple Citrix customers worldwide, prompting some administrators to take appliances offline. Citrix has published indicators of compromise.
- Two NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, actively exploited.
- CVE-2026-88771 is unauthenticated RCE affecting default NetScaler ADC/Gateway configurations.
- CISA added both to KEV and warned of global active exploitation.
- NCSC-NL TLP:AMBER tip reported victims at multiple Citrix customers; some admins shut appliances down.
- Citrix published IoCs and patched eight total NetScaler vulnerabilities.
Vulnerabilities mentionedAll →
- CVE-2026-194909.37%Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway KEV PoC
Full article362 words · extracted from securityweek.com · click to collapse
Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.
The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.
The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5.
CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration.
CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.
Citrix has made available indicators of compromise (IoCs).
Advertisement. Scroll to continue reading.
Over the weekend, NetScaler administrators said on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why.
Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions.
According to a copy posted in the Reddit thread, NCSC-NL said it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. Several admins took their NetScalers offline, while others said they had received no official notice.
CISA rushed to add CVE-2026-88771 and CVE-2026-88772 to its KEV catalog. The agency also issued an alert, warning that “threat actors are actively exploiting these vulnerabilities globally.”
“Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching,” CISA said.
CISA’s KEV catalog currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added CVE-2026-19490 and CVE-2026-8452.
Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs