Citrix patches two critical NetScaler zero-days after exploits observed
Citrix patched two critical NetScaler ADC and Gateway zero-days, CVE-2026-88771 and CVE-2026-88772, after exploits were observed. CISA gave federal agencies until Sept. 30 to fix them.
In a weekend security advisory, Citrix identified the flaws as CVE-2026-88771 and CVE-2026-88772. The first is an improper input validation vulnerability that allows unauthenticated attackers to execute arbitrary commands remotely. The second is a buffer overflow or memory-corruption flaw that could let remote attackers run malicious code or cause a denial of service. Both carry a severity score of 9.5 out of 10.
The flaws affect NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. Citrix issued patches in NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, along with corresponding FIPS builds.
Citrix said exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. The company urged organizations to apply the fix as soon as possible to defend their premises from potentially disruptive attacks.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on Sunday and gave Federal Civilian Executive Branch agencies a three-day deadline, until Wednesday, Sept. 30, to patch them. The Dutch National Cyber Security Center reportedly notified organizations in the Netherlands before Citrix publicly disclosed the flaws, according to BleepingComputer. Multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT about two vulnerabilities that could independently lead to remote code execution, BleepingComputer reported.
Before Citrix confirmed the flaws, administrators reported warnings. According to BleepingComputer, Citrix admins took to Reddit to say IT suppliers and security teams had contacted their organizations and recommended shutting down NetScaler appliances. One administrator wrote that their IT supplier's security team could not give details but advised shutting down Netscalers immediately. Other admins said similar warnings came from law enforcement, national cybersecurity agencies and CERTs. Security experts watchTowr said they were rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities were circulating in the wild, adding that details were scarce but the information was credible.
NetScaler appliances are frequent targets because they provide remote access to internal applications and desktops and are exposed to the internet, allowing direct attack. Vulnerabilities that bypass authentication or enable remote code execution can give attackers a foothold without victim interaction. From there, attackers could steal credentials, access internal resources or move laterally to deploy ransomware. The appliances can also be harder to monitor than standard endpoints because organizations often deploy extensive security tools for computers and servers while specialized networking devices receive less visibility. This is not the first time cybercriminals have targeted NetScaler appliances, and internet exposure, privileged access and limited visibility make serious NetScaler vulnerabilities attractive to both state-sponsored actors and profit-oriented groups.