Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

Citrix customers are reeling after two critical zero-day vulnerabilities were exploited, leaving their networks vulnerable to remote code execution and denial-of-service attacks. The company’s NetScaler products, used for application delivery control and security, were targeted by attackers who essentially gained a “skeleton key” to affected systems.

The two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both have a CVSS score of 9.5, indicating their high severity. The flaws stem from improper input validation in the case of the first vulnerability, while the second is a memory overflow issue that can lead to remote code execution and denial-of-service attacks. Both vulnerabilities affect default configurations of Citrix’s NetScaler Application Delivery Control (ADC) and Gateway products.

Citrix was aware of the exploitation activity as early as last week, but it didn’t disclose the zero-days until September 27, when it released patches for affected customers. However, reports of possible exploitation first surfaced online on September 25 in a Reddit thread, where several users noted that IT providers and security teams were urging them to disable their NetScaler appliances.

Benjamin Harris, founder and CEO of watchTowr, said the rumors of zero-day attacks on NetScaler customers were true. “While details are scarce, we have now confirmed the rumors with authoritative sources,” he wrote in a LinkedIn post on September 26. Harris emphasized that hours do matter in today’s cyber-threat landscape, where exploitation windows are rapidly shrinking.

The situation has raised questions about Citrix’s communication and response to the zero-day vulnerabilities. While the company didn’t respond to Dark Reading’s questions about when it became aware of the exploitation activity or the scope of the attacks, a report from Google’s Threat Intelligence Group (GTIG) said the campaign has been “ongoing since at least early September.”

The exploitation of these vulnerabilities highlights the importance of timely patch management and vulnerability disclosure. In this case, Citrix’s silence on the reported attacks may have left customers vulnerable for several days. This incident serves as a reminder that zero-day exploits can happen quickly, and it’s essential to stay vigilant and up-to-date with security patches.

For readers, this incident underscores the importance of regular software updates and patch management. In addition to keeping your systems patched, it’s crucial to monitor your network for suspicious activity and follow best practices for vulnerability disclosure. If you’re a Citrix customer, take immediate action to update your NetScaler appliances and ensure that your security teams are aware of any potential risks.


Source: Dark Reading — 2026-09-29