Skip to content
Citrix Zero-Day Vulnerabilities: Critical Patches Released After Active Exploitation

Citrix Zero-Day Vulnerabilities: Critical Patches Released After Active Exploitation

Redpacketsecurity •admin • September 29, 2026

Citrix has released security updates for eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Two critical Citrix zero-day vulnerabilities have been exploited in the wild, prompting the vendor and government cybersecurity agencies to urge affected organizations to patch promptly.

In a security bulletin published on September 27, Citrix disclosed eight flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Their CVSS scores range from 7 to 9.5.

The two most urgent vulnerabilities are:

CVE-2026-88771: An unauthenticated remote code execution (RCE) vulnerability caused by improper input validation. It could allow an attacker to run arbitrary commands and affects all NetScaler ADC and NetScaler Gateway deployments using the default configuration.

CVE-2026-88772: A memory overflow flaw that could result in RCE or denial of service. It affects deployments with DTLS enabled, including VPN vServers, where DTLS is enabled by default.

Citrix said it had observed exploitation of both CVE-2026-88771 and CVE-2026-88772 on unpatched NetScaler deployments. The company strongly urged affected customers to install the relevant updated versions as soon as possible.

Another high-priority issue is CVE-2026-88773 , a critical HTTP request smuggling vulnerability with a CVSS score of 9.3. It affects NetScaler ADC and NetScaler Gateway when HTTP configuration is enabled.

Reports of exploitation had circulated before Citrix published its bulletin. On September 28, the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) issued a critical alert urging organizations to apply the updates. Online reports also indicated that the Dutch National Cyber Security Center (NCSC-NL) had alerted organizations in the Netherlands.

The US Cybersecurity and Infrastructure Security Agency (CISA) directed federal agencies to patch by Wednesday, 30 September. The identity of those behind the exploitation attempts is not clear. In 2025, however, a cyber intrusion linked to China-based group Salt Typhoon targeted a Citrix zero-day vulnerability.

The Remaining Five Vulnerabilities

The other five vulnerabilities in the Citrix security bulletin are:

CVE-2026-88774: A feature policy bypass caused by improper use of an HTTP URL-based expression (CVSS 7).

CVE-2026-88775: A memory overflow flaw that may cause unpredictable or erroneous behavior, or denial of service (CVSS 8.8).

CVE-2026-88776: A memory overflow flaw that may cause unpredictable or erroneous behavior, or denial of service (CVSS 8.8).

CVE-2026-88777: A memory overflow flaw that may cause unpredictable or erroneous behavior, or denial of service (CVSS 8.8).

CVE-2026-88778: A TCP Initial Sequence Number (ISN) prediction vulnerability (CVSS 8.8).

Citrix clarified that the bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by Cloud Software Group with the required software updates.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.