Skip to content
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero

Citrix Confirmed Two New NetScaler Flaws Exploited as Zero

Securityaffairs.Co •Pierluigi Paganini • September 27, 2026

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code.

Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The first warnings did not come from Citrix. On September 26, administrators said IT providers and security teams were privately advising them to take NetScaler systems offline, sometimes without explaining why.

The two zero-day issues are not related to NetScaler vulnerabilities CVE-2026-19490 and CVE-2026-19489 that were disclosed in August.

The reports show how the attacks were already underway while defenders were still waiting for official details and fixes.

Security researchers at watchTowr then confirmed that the reports were credible. The company said it was investigating reports of multiple unpatched NetScaler remote code execution flaws being exploited in the wild and later said the vulnerabilities had been found during forensic investigations.

“We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible,” watchTowr wrote on X .

The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands. According to a notice seen by BleepingComputer , a European partner CERT had shared information two critical NetScaler zero-days that could allow remote code execution. One of the flaws could even let an attacker inject shellcode directly into memory.

That warning has now become a confirmed security incident.

Citrix published fixes for the two exploited vulnerabilities on September 27, along with patches for six other security issues. The company confirmed that both NetScaler flaws had been exploited against systems that had not been mitigated, although it hasn’t said how many organizations were affected, who was behind the attacks or when exploitation started.

“Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.” reads the advisory . “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. “

Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible.

“Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.” Continue the advisory.

The first vulnerability, CVE-2026-88771, involves improper input validation and allows an unauthenticated attacker to execute arbitrary commands, and Citrix says it affects all NetScaler ADC and NetScaler Gateway deployments in the affected versions without requiring an additional feature to be enabled.

The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled. That’s particularly relevant for NetScaler Gateway because DTLS is enabled by default for VPN virtual servers unless an administrator has explicitly disabled it.

NetScaler sits at a particularly sensitive point in many corporate networks. These appliances provide VPN and remote access, load balancing and authentication, so compromising one can give an attacker a useful position at the edge of an organization.

Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases. Fixes are also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches.

There’s an important detail for organizations that patched NetScaler last month. The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability CVE-2026-19490 , are still within the affected range for these new flaws. Installing those earlier builds doesn’t address the two newly disclosed vulnerabilities.

The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15. The new security fix still covers it, but organizations running that branch should factor its maintenance status into their upgrade planning.

But patching the two zero-days is only half the job.

Citrix is providing generic Indicators of Compromise (IoCs) through NetScaler Console to help customers quickly assess whether their NetScaler deployments may have been compromised.

The feature is available in NetScaler Console service and on-premises deployments with Cloud Connect, starting with version 14.1-73.36, and requires the telemetry channel to be enabled. Customers can launch scans from the Security Advisory page once the IoC detection logic is released. Those without NetScaler Console can Citrix Support for access and assistance. Citrix warns that the IoCs do not cover all attacker techniques and may miss compromises, so experienced forensic investigators should be involved when needed.

Follow me on Twitter: @securityaffairs and and Mastodon

( SecurityAffairs – hacking, )