Two Critical NetScaler Zero-Days Confirmed Exploited in Wild – Urgent Patching Recommended
Citrix has issued emergency patches for two critical vulnerabilities affecting its NetScaler appliances, following reports of exploitation in the wild. The two zero-days, tracked as CVE-2026-88771 and CVE-2026-88772, have a CVSS score of 9.5 each and can be exploited without authentication.
The affected vulnerabilities are related to remote code execution and memory overflow issues, which can lead to serious consequences such as data breaches or system crashes. The patches address eight critical vulnerabilities in total, including HTTP request smuggling, Denial-of-Service (DoS), and security bypass issues.
Citrix has made available indicators of compromise (IoCs) for its customers to detect potential exploitation attempts. However, some NetScaler administrators reported receiving warnings from their IT suppliers, CERT teams, and Managed Detection and Response (MDR) providers to shut down their appliances immediately, often without explaining why.
The Dutch National Cyber Security Centre (NCSC-NL) reportedly shared a private pre-notification with its European partners, which was then passed on to some NetScaler administrators. The NCSC-NL stated that it had learned of the two zero-days from a European partner CERT and that exploitation had been identified at multiple Citrix customers worldwide.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and issued an alert, warning that threat actors are actively exploiting these vulnerabilities globally. CISA urges users and administrators to review Citrix’s advisories and patch their NetScaler appliances as soon as possible.
It’s worth noting that this is not the first time Citrix has faced criticism for its vulnerability management practices. In recent months, CISA has added over a dozen Citrix NetScaler vulnerabilities to its KEV catalog, highlighting the importance of timely patching and vulnerability disclosure.
In light of these developments, it’s essential for all NetScaler administrators to review their appliance configurations and apply the latest patches as soon as possible. This will help prevent potential exploitation attempts and minimize the risk of data breaches or system crashes.
Practical takeaway: If you’re a NetScaler administrator, take immediate action to patch your appliances against these critical vulnerabilities. Review Citrix’s advisories and check for indication of compromise prior to patching. Don’t wait – urgent patching is recommended to prevent potential exploitation attempts.
Source: SecurityWeek — 2026-09-28