Skip to content
Dual NetScaler Zero

Dual NetScaler Zero

Darkreading •Rob Wright • September 28, 2026

The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

Citrix on Sept. 27 disclosed two critical NetScaler zero-day vulnerabilities after reports of exploitation had caused alarm among customers for several days.

CVE-2026-88771 is a remote code execution (RCE) flaw with a 9.5 CVSS score that stems from improper input validation, while CVE-2026-88772 is a memory overflow vulnerability, also with a 9.5 CVSS score, that can lead to RCE and distributed denial-of-service (DDoS) attacks. Both zero-days affect default configurations of Citrix's NetScaler Application Delivery Control (ADC) and Getaway products.

"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in its advisory , which strongly urged customers to update their software.

However, public reports of possible exploitation first surfaced online on Sept. 25 in a thread, and there's additional evidence that attacks began "at least a week ago," according to Benjamin Harris, founder and CEO of watchTowr.

Related: AI Agents Are Privileged Users; Who Is Auditing Their Access?

Communication Breakdowns for NetScaler Attacks

On Sept. 25, several Citrix users noted on that IT providers and security teams were urging them to disable their NetScaler appliances. Additionally, one user posted a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL) warning of possible NetScaler zero-day attacks, but it was later deleted. According to an FAQ from Tenable on the exploitation activity, the alert was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions, which limit the public sharing of such information.

On Sept. 26, watchTowr warned of potential zero-day attacks on NetScaler customers in social media posts. "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild," the company said in a post on X . "While details are scarce, the information is credible."

Later that day, Harris posted on that the rumors were true. "While details are scarce, we have now confirmed the rumors with authoritative sources," he wrote. "Please, take this seriously and pull NetScaler appliances offline immediately."

However, Citrix didn't disclose the zero-days until the following day, along with several other NetScaler flaws, and released patches. But Harris notes that, according to authoritative sources like national CERTs , exploitation had begun at least a week ago. Similarly, GreyNoise said in a blog post yesterday that it first detected exploitation on Sept. 24.

Related: Cisco Zero-Day Highlights API Endpoint Authentication Issues

Confusion as Citrix Remained Quiet on Zero-Day Rumors

Harris takes issue with Citrix's silence on the reported attacks, emphasizing that in today's cyber-threat landscape with rapidly shrinking exploitation windows, "hours do matter," to say nothing of several days.

"It's not unusual for zero-days to be exploited; we see that time and time again," he tells Dark Reading. "But I think what's typically done in those situations is that you make users aware that there is a risk that is currently kind of unmanageable, and of course I think that's what's frustrating people today."

Harris also said that the patch watchTowr's team analyzed for a technical analysis of CVE-2026-88771 published yesterday was dated Sept. 24, which indicates Citrix had knowledge of the exploitation activity last week, though the timing is unclear.

Dark Reading contacted Citrix for on when the company became aware of the exploitation activity, as well as the scope of the attacks. The software maker did not respond to those questions and provided the following statement:

"We recently identified critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway that led us to immediately develop and release a new version of the software that addresses the issues. We always advise customers to promptly adopt the latest version of our software, and we are underscoring that guidance here to ensure our customers immediately benefit from the updates in this latest release."

Related: MFA Won't Save You From OAuth Consent Abuse

Harris criticized Citrix for remaining quiet on the zero-day rumors, which he says seems "almost purposeful," and says the company should have acted sooner to provide customers with clarity the situation. Instead, NetScaler administrators found themselves in a pickle, relying on rumored attacks and debating whether to disable their appliances across their networks.

"One the rumors begin, don't let people just panic," he says.

Risks to NetScaler Customers

Harris says the two zero-day vulnerabilities are particularly dangerous for enterprises because they impact default configurations for NetScaler products and they are both trivial to exploit.

"If it's on the Internet, it is vulnerable," he says, adding that the stars aligned in a way that could not be much worse for customers.

First, he notes, NetScaler is used by many large organizations and enterprises, including many in the critical infrastructure space, which gives attackers high-value targets. "You've also got clearly a capable attacker, and you've got an attacker that basically has a skeleton key to every organization running a Citrix NetScaler, and they're actually using it," he says.

Palo Alto Networks, meanwhile, reported that its scans revealed more than 50,000 exposed NetScaler instances on the Internet. While disabling all NetScaler appliances across an organization may seem drastic, Harris says that in this case, it may be justifiable. If organizations cannot update to fixed versions of NetScaler ADC and Gateway, they should consider disabling the products.

Senior News Director, Dark Reading

Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.

Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.

At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

Effective Alert Triage: Reducing Noise and Finding Real Threats

Effective Alert Triage: Reducing Noise and Finding Real Threats

Cybersecurity Outlook 2027

Cybersecurity Outlook 2027

Threat Exposure Analytics: Measuring and Communicating Security Risk

Threat Exposure Analytics: Measuring and Communicating Security Risk

Benchmark Scores Are a False Flag

Benchmark Scores Are a False Flag

Building an Effective Red Team: Beyond Penetration Testing

Building an Effective Red Team: Beyond Penetration Testing

Cheap Hardware Module Bypasses AMD, Intel Memory Encryption

Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs

'TruffleNet' Attack Wields Stolen Credentials Against AWS

Microsoft Issues Emergency Patch for Critical Windows Server Bug

Extracted Entities