Citrix Confirms Critical Zero-Day Exploits Against NetScaler Appliances, Urges Immediate Action
In a disturbing development, Citrix has confirmed that two critical zero-day exploits are being actively used against its NetScaler appliances, putting thousands of organizations worldwide at risk. The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, have been privately warned about by cybersecurity researchers, IT providers, and national cybersecurity agencies for several days, but only now has Citrix officially acknowledged the issue.
The affected NetScaler appliances are commonly deployed as Internet-facing edge devices that provide remote access and application delivery services for internal corporate networks. Compromising one of these devices can grant attackers an initial foothold at the perimeter of a victim’s network, potentially providing a path to internal systems without first compromising an endpoint inside the organization.
The severity of this threat cannot be overstated. The two zero-day exploits, both with a severity score of 9.5, allow attackers to execute arbitrary commands or cause a denial-of-service condition. CVE-2026-88771 is caused by improper input validation, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution when DTLS is enabled on the affected device.
Citrix has released security updates to address the vulnerabilities, and organizations are urged to take immediate action to protect themselves. The patches apply to all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and do not require any additional feature to be enabled. Affected versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23, and NetScaler ADC FIPS before 14.1-73.37 FIPS.
In a bizarre twist, it appears that national cybersecurity agencies were aware of the threat even before Citrix publicly disclosed it. The Dutch National Cyber Security Center (NCSC-NL) reportedly sent pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days, prompting concerns that sensitive information may have been compromised before the official disclosure.
Citizens and organizations worldwide must take immediate action to protect their networks from this emerging threat. This means applying security updates as soon as possible and verifying that all NetScaler appliances are running on patched versions. Furthermore, it is essential for IT teams to review their current configurations and ensure that all necessary patches have been applied. In a world where cyber threats are increasingly sophisticated, vigilance and proactive measures are more crucial than ever.
In the face of this emerging threat, it is imperative that organizations prioritize patching their NetScaler appliances and remain vigilant against potential attacks. By doing so, they can minimize the risk of data breaches and ensure business continuity in an increasingly complex cybersecurity landscape.
Source: Bleeping Computer — 2026-09-27