Skip to content

Citrix NetScaler Zero Days Exploited Globally as CISA Urges Immediate Action

Newsaffinity • September 28, 2026

WASHINGTON, U.S. — Citrix has confirmed that attackers are exploiting two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway products before organizations had access to fixes. The vulnerabilities, tracked as CVE 2026 88771 and CVE 2026 88772 , can enable remote code execution and have been observed across multiple customer environments.

The disclosures have triggered warnings from the U.S. Cybersecurity and Infrastructure Security Agency, which added both vulnerabilities to its Known Exploited Vulnerabilities catalog after receiving intelligence confirming active exploitation globally.

Two critical vulnerabilities under active exploitation

CVE 2026 88771 is an improper input validation vulnerability with a CVSS 4.0 score of 9.5. According to Citrix, an unauthenticated attacker can exploit the vulnerability to execute arbitrary commands on an affected NetScaler appliance. Importantly, the flaw affects NetScaler ADC and Gateway deployments in their default configuration and does not require an additional feature to be enabled.

CVE 2026 88772 also carries a 9.5 CVSS score. It involves a memory overflow that can result in remote code execution or denial of service. The vulnerability requires DTLS to be enabled, although Citrix notes that DTLS is enabled by default on VPN virtual servers.

Citrix has confirmed that exploitation of both vulnerabilities has been observed on unmitigated deployments.

Why NetScaler vulnerabilities are particularly significant

NetScaler appliances commonly operate at the edge of enterprise networks, supporting application delivery, remote access and VPN services. This positioning can make a compromised appliance particularly valuable to attackers because it sits between external connections and internal corporate infrastructure.

The Canadian Centre for Cyber Security said successful exploitation of CVE 2026 88771 could result in complete compromise of an affected appliance, unauthorized access to applications and services, credential theft and potential lateral movement into internal systems.

The agency also said reports have identified exploitation across multiple Citrix customer environments worldwide, although the full scale of the activity remains unknown.

That uncertainty adds another layer to the incident because organizations cannot assume that an affected appliance has remained uncompromised simply because it has now been patched.

CISA calls for investigation alongside patching

CISA has urged organizations to review Citrix’s security guidance and, where possible, check for indicators of compromise before applying updates. The agency specifically highlighted the importance of preserving forensic evidence because updating affected appliances can potentially remove information useful to an investigation.

Citrix has also published indicators of compromise and recommends customers install the relevant fixed builds as soon as possible. The vendor states that NetScaler ADC and Gateway versions 14.1 before 14.1 73.37 and 13.1 before 13.1 64.23 are affected, with separate fixed builds available for FIPS and NDcPP deployments.

Organizations that suspect compromise may therefore need to balance immediate remediation with incident response and evidence preservation.

Security teams face a wider NetScaler exposure

The two zero days are part of a broader security disclosure covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway. The additional flaws include an HTTP request smuggling vulnerability, policy bypass issues and other memory related vulnerabilities.

The urgency around the incident reflects a broader challenge for organizations operating internet facing infrastructure. Security teams must not only identify vulnerable systems but also determine whether attackers accessed them before patches were available.

With exploitation already confirmed, the Citrix NetScaler incident puts renewed attention on perimeter appliances that provide remote access to enterprise environments. For affected organizations, remediation now involves both applying vendor updates and determining whether existing systems show evidence of compromise.