Citrix Confirms Two NetScaler Zero-Day RCEs, Rushes Patches

Citrix confirmed on September 27 that CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days and shipped emergency NetScaler fixes.

Read as article

Citrix Confirms Two NetScaler Zero-Day RCEs, Rushes Patches

By @sharedot · · 8 pages

Citrix confirmed on September 27 that CVE-2026-88771 and CVE-2026-88772 were exploited as zero-days and shipped emergency NetScaler fixes.

What happened: two exploited zero-days confirmed

On September 27, Citrix published bulletin CTX697096 confirming that two critical NetScaler remote code execution flaws were exploited in attacks and releasing fixes for them plus six other vulnerabilities. CVE-2026-88771 is an improper input validation flaw letting an unauthenticated attacker execute arbitrary commands; it affects all NetScaler ADC and Gateway deployments, including default configurations, with no extra feature required. CVE-2026-88772 is a memory overflow allowing RCE or denial of service when DTLS is enabled — and DTLS is on by default for VPN virtual servers. Citrix said only that exploits 'have been observed' on unmitigated deployments, offering no detail on scope, timing, or attribution.

Why the weekend scramble was unusual

Rescana reports that CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog on September 27 with a September 30 remediation deadline under BOD 26-04 guidance. The Dutch NCSC-NL reportedly sent pre-notifications to Dutch organizations before Citrix's disclosure, declining to confirm details to BleepingComputer outside its constituency.

No workaround: only fixed builds close the hole

Citrix lists no workaround for either exploited flaw, so upgrading is the only effective fix, according to watchTowr. Affected versions are NetScaler ADC and Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, FIPS builds before 14.1-73.37 FIPS, and FIPS/NDcPP before 13.1-37.279. Secure Private Access Hybrid deployments using NetScaler instances are also affected; Citrix-managed cloud services are being upgraded by the vendor. Notably, The Hacker News reports that appliances on builds 14.1-73.32 and 13.1-63.21 — which fixed the August authentication bypass CVE-2026-19490 — still fall inside the affected range. There is also a 13.1 upgrade caveat: appliances with configured variables should target 13.1-64.24 to avoid a reboot loop, per The Cyber Security Hub.

Why NetScaler is such a valuable target

NetScaler appliances sit at the network edge, terminating VPN sessions, brokering authentication, and load balancing traffic to internal applications. A successful exploit therefore hands an attacker a perimeter foothold and a potential path into internal systems without ever compromising an endpoint, which is why these flaws draw immediate exploitation pressure. The bulletin's six additional flaws — including HTTP request smuggling (CVE-2026-88773, 9.3), a policy bypass, three memory overflows, and TCP ISN prediction (CVE-2026-88778) — depend on specific configurations and are not listed as exploited. watchTowr notes CVE-2026-88778 is closed by enabling Enhanced ISN Generation, not by the upgrade alone, so configuration review matters alongside patching.

Patching alone does not prove you are clean

Because both flaws were exploited before a public fix existed, installing the update cannot reveal whether an attacker got in first. Citrix is providing generic indicators of compromise through NetScaler Console's Security Advisory workflow (version 14.1-73.36 or later, with telemetry), but cautions these checks may miss compromises and recommends experienced forensic investigators. Citrix's suspected-compromise guidance calls for preserving evidence — VPX snapshots, remote syslog logs, support bundles, packet-engine core dumps — before updating, then isolating the device, rotating every stored credential and certificate, and reviewing authentication servers and systems reachable from the appliance. watchTowr advises a clean IOC scan should not be treated as proof the appliance was never accessed.

What comes next for exposed organizations

The response now has two parallel objectives: upgrade to the fixed builds immediately, and determine whether the window of exposure resulted in compromise. Organizations that cannot patch quickly should reduce internet exposure of NetScaler devices while they work, per BleepingComputer. History raises the stakes: the Dutch NCSC's 2025 investigation into CVE-2025-6543 found attackers had erased traces of their activity, and that patching could leave previously established access intact. Neither Citrix nor the reporting outlets identify the responsible actors or the scale of attacks, and those questions remain open. Administrators should verify running builds on every node, hunt for unexpected files, processes and outbound connections, and monitor closely after remediation.

Sources

  1. bleepingcomputer.com › Citrix confirms two NetScaler RCE zero-days exploited in attacks
  2. thehackernews.com › Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
  3. rescana.com › Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Day Vulnerabilities – Urgent Patch Required
  4. watchtowr.com › Citrix NetScaler ADC & Gateway Remote Code Execution Zero-Day Vulnerabilities (CVE-2026-88771, CVE-2026-88772)
  5. linkedin.com › Citrix Releases Emergency NetScaler Patches After Two Zero-Days Exploited In Attacks
  6. cybersecuritynews.com › Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attack

More on Cybersecurity