Citrix Zero-Days: 50,000 NetScaler Devices Exposed

Palo Alto Networks counted more than 50,000 internet-exposed NetScaler instances as CISA set a September 30 patch deadline for federal agencies.

Read as article

Citrix Zero-Days: 50,000 NetScaler Devices Exposed

By @sharedot · · 8 pages

Palo Alto Networks counted more than 50,000 internet-exposed NetScaler instances as CISA set a September 30 patch deadline for federal agencies.

The Scale of Exposure

CyberScoop reports that Palo Alto Networks identified more than 50,000 publicly exposed Citrix NetScaler instances potentially vulnerable to both zero-days as of Sunday. Cybersecurity Dive, citing the Shadowserver Foundation, reports a lower count of more than 20,000 exposed instances — the two trackers differ, so both figures are attributed to their respective publishers. NetScaler ADC and Gateway appliances sit at the network edge, brokering VPN, load balancing and authentication traffic, which makes any unauthenticated remote code execution flaw in them a target of choice for both financially motivated cybercriminals and state-sponsored espionage groups.

A Weekend of Unofficial Warnings

Nearly two days passed between the first unconfirmed rumors on Saturday and Citrix's Sunday advisory, and defenders were forced to act without official confirmation. CyberScoop quotes watchTowr CEO Ben Harris saying customers received warnings through unofficial channels while Citrix remained publicly silent, and that 'when active exploitation is underway, hours matter.' Cybersecurity Dive reports security teams received urgent phone calls on Saturday from IT security firms advising them to disconnect servers, and that the Dutch NCSC issued warnings before Citrix's disclosure. Coalition's Joe Toomey called the vendor 'unconscionably irresponsible' in a LinkedIn post for staying silent more than 36 hours.

The Two Exploited Flaws

Both actively exploited vulnerabilities rate 9.5 on the CVSS scale and allow unauthenticated remote code execution. Cybersecurity Dive describes CVE-2026-88771 as a remote code execution flaw from improper input validation and CVE-2026-88772 as a memory overflow leading to RCE or denial of service; Network World adds that CVE-2026-88771 affects all NetScaler appliances in default configuration, and that CVE-2026-88772's precondition is met when DTLS is enabled, which it is by default on VPN virtual servers. Citrix also patched six more defects, including a 9.3-rated HTTP request-smuggling bug, CVE-2026-88773, Network World reports. The earliest observed attempt came September 24, which CyberScoop notes GreyNoise saw — a failed attempt that researchers warn almost certainly predates the real start of exploitation.

Washington and Allies React

CISA issued an alert Sunday after Citrix confirmed the exploitation and added both CVEs to its Known Exploited Vulnerabilities catalog. TechRadar reports the KEV listing gives Federal Civilian Executive Branch agencies a three-day deadline, until Wednesday, September 30, to patch. Citrix has now appeared on CISA's KEV list five times this year and 26 times since late 2021, CyberScoop notes. Abroad, the Australian Signals Directorate's ACSC issued a critical alert, and NCSC-NL had already notified Dutch organizations, while the UK's NCSC urged organizations to identify exposed appliances and isolate affected systems where practical.

Patching Is Not a Clean Bill of Health

Because exploitation began before fixes existed, upgrading does not prove an appliance was never breached. Cybersecurity Dive reports Citrix's prior compromise guidance calls for snapshotting a compromised virtual instance, revoking credentials, and isolating the device. CyberSecurityNews adds that defenders should preserve logs and evidence, hunt with Citrix's generic indicators of compromise available via NetScaler Console, verify every node in high-availability pairs, and forward logs to an external SIEM — with the caveat that a clean IOC scan should not be treated as proof an appliance was not compromised. Citrix has not said how many customers were compromised, CyberScoop reports, and attribution remains under investigation.

A Familiar Pattern for Citrix

This is Citrix's second NetScaler emergency in barely a month — Network World notes Citrix patched two other critical holes in the appliances a month prior — and the vendor's products have been repeatedly hit in past sprees including the infamous CitrixBleed campaigns. Infosecurity Magazine recalls that a 2025 intrusion linked to the China-based Salt Typhoon group targeted a Citrix zero-day. CyberScoop quotes Harris saying Citrix has a history of delaying publication even when flaws are exploited in the wild, and that the latest incident raises serious questions about whether the vendor has meaningfully improved how it protects and informs customers. Defenders should keep monitoring Citrix's bulletin as threat intelligence develops.

Sources

  1. cyberscoop.com › Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings
  2. cybersecuritydive.com › Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts
  3. networkworld.com › NetScaler admins told to patch critical zero-days in ADC and Gateway now
  4. techradar.com › Citrix says two worrying NetScaler RCE zero-days exploited in attacks
  5. infosecurity-magazine.com › Citrix Patches Critical Zero Days Under Active Exploitation
  6. cybersecuritynews.com › NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities

More on Cybersecurity

Citrix Zero-Days: 50,000 NetScaler Devices Exposed · ShareDot