Citrix’s NetScaler Customers Left Reeling as Zero-Day Vulnerabilities Exposed
A pair of zero-day vulnerabilities in Citrix’s NetScaler products has sent shockwaves through the cybersecurity community, leaving customers scrambling to patch their systems and protect against potential attacks. The critical flaws, which affect default configurations of NetScaler appliances, have been exploited by attackers for at least a week, causing alarm among Citrix customers.
The two zero-day vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, allow attackers to execute malicious code on affected systems, potentially leading to remote code execution (RCE) and distributed denial-of-service (DDoS) attacks. Both flaws have a CVSS score of 9.5, indicating their severity. Citrix’s advisory strongly urged customers to update their software, but it seems that the company was aware of the exploitation activity as early as last week.
Benjamin Harris, founder and CEO of watchTowr, has been vocal about his concerns regarding Citrix’s handling of the situation. “Hours do matter” in today’s cyber-threat landscape, he emphasized, where rapidly shrinking exploitation windows require swift action from vendors to mitigate potential attacks. Harris also noted that Citrix had knowledge of the exploitation activity last week, as evidenced by a patch watchTowr’s team analyzed for a technical analysis of CVE-2026-88771.
The exploit has been circulating in the wild since at least early September, according to Google’s Threat Intelligence Group (GTIG), which detected exploitation of CVE-2026-88772 in late September. GTIG and Mandiant first observed signs of the campaign in early September, highlighting the need for swift action from vendors to protect their customers.
Citrix has faced criticism for its handling of the situation, with some accusing the company of being slow to respond to the potential attacks. Harris emphasized that in today’s fast-paced cyber-threat landscape, “it’s not unusual for zero-days to be exploited.” However, he stressed that vendors should make users aware of potential risks and take swift action to mitigate them.
The exploitation activity has been characterized by a lack of transparency, with some reports suggesting that the Dutch National Cyber Security Centre (NCSC-NL) had warned Citrix customers of possible NetScaler zero-day attacks. However, this alert was later deleted due to restrictions on public sharing of sensitive information.
Citrix customers would do well to take heed of Harris’s advice and prioritize patching their systems as soon as possible. With the potential for RCE and DDoS attacks still present, swift action is essential to protect against these exploits. As Harris noted, “hours do matter” in today’s cyber-threat landscape, where vendors must be proactive in protecting their customers from emerging threats.
Source: Dark Reading — 2026-09-29