DKDKCISSPSearch
Vulnerabilities

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

DKCISSP News DeskBleepingComputer27 Sept 2026, 9:32 pm
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.

NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks.

The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.

Cybersecurity firm watchTowr later publicly warned that it was that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.

Citrix has now published security bulletin CTX697096 , confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.

Compromising one of these devices can give attackers an initial foothold at the perimeter of a victim's network and potentially provide a path to internal systems without first compromising an endpoint inside the organization.

Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.

CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation, allowing an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also with a severity score of 9.5.

This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway.

Citrix has confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.

Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled.

What happened

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

The vulnerabilities are the same zero-days that cybersecurity researchers, IT providers, and national cybersecurity agencies began privately warning organizations about over the weekend.

NetScaler appliances are particularly valuable targets because organizations commonly deploy them as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks.

What changed

The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.

Cybersecurity firm watchTowr later publicly warned that it was that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.

Citrix has now published security bulletin CTX697096 , confirming the vulnerabilities and releasing patches for affected NetScaler ADC and NetScaler Gateway appliances.

Who is affected

Compromising one of these devices can give attackers an initial foothold at the perimeter of a victim's network and potentially provide a path to internal systems without first compromising an endpoint inside the organization.

Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.

Why it matters

CVE-2026-88771 is a remote code execution vulnerability caused by improper input validation, allowing an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service condition, also with a severity score of 9.5.

Technical details

This vulnerability can be exploited when DTLS is enabled on a NetScaler ADC or NetScaler Gateway.

Citrix has confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.

Cloud Software Group is upgrading Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Response

Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any additional feature to be enabled.

Secure Private Access Hybrid deployments using NetScaler instances are also affected and must be upgraded to the recommended builds.

What security teams should do

The security bulletin also fixes six other NetScaler vulnerabilities, bringing the total to eight flaws fixed in this update.

The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation.

Attribution

BleepingComputer: Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 amKiteworks patches max severity code injection vulnerabilityBleepingComputer · 1 Oct 2026, 7:21 pm