Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild. The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, denial of service (DoS), and security bypass issues.

The two confirmed zero-days are tracked as CVE-2026-88771 and CVE-2026-88772, both with a CVSS score of 9.5. These vulnerabilities can be exploited remotely without authentication, putting all NetScaler ADC and Gateway deployments at risk. CVE-2026-88771 is a remote code execution vulnerability that affects all NetScaler appliances, including those in the default configuration. CVE-2026-88772, on the other hand, is a memory overflow vulnerability that affects appliances with DTLS (Datagram Transport Layer Security) configuration enabled, which is the default setting for VPN virtual servers.

The Dutch National Cyber Security Centre (NCSC-NL) reportedly shared a private pre-notification about the two zero-days to European partner CERTs and MDR providers. This warning was shared under TLP:AMBER restrictions, indicating that it contained sensitive information that should only be shared with trusted parties. Several NetScaler administrators took their appliances offline after receiving warnings from their IT suppliers, CERT teams, and MDR providers.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added the two vulnerabilities to its KEV catalog and issued an alert warning of active exploitation. CISA urges users and administrators to review Citrix’s advisories and check for indicators of compromise prior to patching. This is not the first time that Citrix NetScaler vulnerabilities have been added to the KEV catalog, as over a dozen other vulnerabilities have been listed in recent months.

The rapid development and exploitation of these zero-days highlights the importance of staying up-to-date with security patches and alerts. Administrators should regularly review vendor advisories and apply patches promptly to prevent potential attacks. It also emphasizes the need for better communication between vendors, CERTs, and MDR providers to prevent similar incidents in the future.

To stay safe, NetScaler administrators should immediately apply the available patches for CVE-2026-88771 and CVE-2026-88772. They should also review Citrix’s advisories and check their appliances for signs of compromise. Additionally, they should consider implementing additional security measures, such as network segmentation and monitoring, to prevent potential attacks. By taking these steps, administrators can help protect their organizations from the risks associated with these critical vulnerabilities.


Source: SecurityWeek — 2026-09-28