Citrix has confirmed that attackers are actively exploiting two critical zero-day vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances.
The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, can lead to remote code execution on vulnerable systems. Citrix published fixes on September 27, 2026 and urged affected customers to upgrade as soon as possible.
What Citrix confirmed
Citrix states that exploitation of both CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated NetScaler deployments. The company classifies the vulnerabilities as critical and says they affect supported customer-managed versions of NetScaler ADC and NetScaler Gateway.
CVE-2026-88771 affects default NetScaler configurations and does not require an additional feature to be enabled. CVE-2026-88772 can also lead to remote code execution or denial of service under affected configurations.
Affected NetScaler versions
Citrix lists the following affected versions:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
- NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Secure Private Access Hybrid deployments that use NetScaler instances are also affected and should be updated to the recommended builds.
Why this is urgent
NetScaler appliances often sit at the edge of enterprise networks and can handle VPN access, authentication, application delivery, and remote connectivity. A remotely exploitable flaw in this position can provide attackers with a path into sensitive internal systems.
Security researchers at watchTowr reported that the vulnerabilities were being exploited before public patches and CVE details were available. Citrix later confirmed exploitation and released the fixed builds.
What organizations should do now
Organizations running affected NetScaler systems should install the Citrix updates immediately. Systems exposed to the internet should receive the highest priority.
Administrators should also preserve logs and forensic evidence, review appliances for signs of compromise, rotate credentials and secrets that may have been accessible through the affected systems, and verify that management interfaces are not exposed unnecessarily.
A clean indicator-of-compromise check should not be treated as proof that a system was never accessed. Citrix customers should follow the vendor’s current security guidance and incident-response recommendations.
What remains unknown
Public reporting has not established the full number of organizations compromised or publicly attributed the attacks to a specific threat actor. Those details may change as incident-response investigations continue.
Sources
Citrix Security Bulletin CTX697096
watchTowr: Citrix NetScaler Zero-Day RCE FAQ
BleepingComputer: Citrix admins warned over exploited NetScaler zero-days