Citrix patches two actively exploited NetScaler zero-days enabling unauthenticated remote code execution
Citrix confirmed two critical NetScaler ADC and Gateway zero-days, CVE-2026-88771 and CVE-2026-88772, were exploited in the wild for unauthenticated remote code execution before patches shipped.
- Victim
- Citrix NetScaler
On 27 September 2026, Citrix confirmed that two critical zero-day vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances โ tracked as CVE-2026-88771 and CVE-2026-88772 โ had been exploited in the wild before fixes were available. The company published patched builds in security bulletin CTX697096 the same day, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its Known Exploited Vulnerabilities catalog, warning that "threat actors are actively exploiting these vulnerabilities globally."
Both bugs are rated critical, with a CVSSv4 score of 9.5, and each can independently enable remote code execution on an affected appliance. CVE-2026-88771 stems from improper input validation and lets an unauthenticated attacker run arbitrary commands; CVE-2026-88772 similarly enables remote code execution or denial of service. Researchers at watchTowr, who discovered the issues during a forensic investigation, and vendors including Rapid7 warned that exploitation of CVE-2026-88771 works against NetScaler deployments in their default configuration with low attack complexity, making reliable exploitation likely against any exposed, unpatched appliance.
Emergency response
The zero-days first surfaced on 26 September, when NetScaler administrators reported being told by suppliers and security teams to shut their appliances down following a confidential pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). Citrix released fixed builds โ NetScaler ADC and Gateway 14.1-73.37 and later, and 13.1-64.23 and later โ on 27 September. CISA urged defenders to check for indicators of compromise before patching, because applying updates can erase the forensic evidence needed to determine whether an appliance was already breached.
Why it matters
NetScaler gateways sit at the network edge and broker remote access, making them a perennial, high-value target for both espionage crews and ransomware affiliates who prize a durable foothold. A pre-authentication remote-code-execution flaw on such a device is close to a worst case, and by 29 September security firms reported that exploitation had escalated into mass, opportunistic attacks against internet-exposed appliances. With unpatched systems still being targeted and compromise assessments ongoing, the incident's status was recorded as ongoing.
Timeline
NetScaler administrators are urged to shut down internet-facing appliances following a private pre-notification from the Dutch NCSC, as reports of in-the-wild exploitation circulate.
Citrix confirms both flaws and releases fixed builds in security bulletin CTX697096; CISA adds the CVEs to its Known Exploited Vulnerabilities catalog.
Security firms report exploitation escalating into mass attacks against unpatched appliances.
Sources
- cisa.govhttps://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
- rapid7.comhttps://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/
- watchtowr.comhttps://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
- support.citrix.comhttps://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscaler-gateway-security-bulletin.html