Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Citrix vulnerability

Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.

The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.

The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5.

CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration.

CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.

Citrix has made available indicators of compromise (IoCs).

Advertisement. Scroll to continue reading.

Over the weekend, NetScaler administrators said on Reddit that their IT suppliers, CERT teams and MDR providers had told them to shut down their appliances immediately, often without explaining why. 

Some of these warnings traced back to a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL), which was reportedly shared under TLP:AMBER restrictions. 

According to a copy posted in the Reddit thread, NCSC-NL said it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide. Several admins took their NetScalers offline, while others said they had received no official notice.

CISA rushed to add CVE-2026-88771 and CVE-2026-88772 to its KEV catalog. The agency also issued an alert, warning that “threat actors are actively exploiting these vulnerabilities globally.”

“Given the potential consequences of successful exploitation and the fact that malicious actors are exploiting at least some of these vulnerabilities, CISA urges users and administrators to review Citrix’s advisories. If possible, users are encouraged to check for indication of compromise prior to patching,” CISA said.

CISA’s KEV catalog currently contains over a dozen Citrix NetScaler vulnerabilities, including the recently added CVE-2026-19490 and CVE-2026-8452.

Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Related: Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.