BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Citrix has confirmed that attackers are actively exploiting two critical zero-day vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, can lead to remote code execution on vulnerable systems. Citrix published fixes on September 27, 2026 and urged affected customers to upgrade as soon as possible.

What Citrix confirmed

Citrix states that exploitation of both CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated NetScaler deployments. The company classifies the vulnerabilities as critical and says they affect supported customer-managed versions of NetScaler ADC and NetScaler Gateway.

CVE-2026-88771 affects default NetScaler configurations and does not require an additional feature to be enabled. CVE-2026-88772 can also lead to remote code execution or denial of service under affected configurations.

Affected NetScaler versions

Citrix lists the following affected versions:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

Secure Private Access Hybrid deployments that use NetScaler instances are also affected and should be updated to the recommended builds.

Why this is urgent

NetScaler appliances often sit at the edge of enterprise networks and can handle VPN access, authentication, application delivery, and remote connectivity. A remotely exploitable flaw in this position can provide attackers with a path into sensitive internal systems.

Security researchers at watchTowr reported that the vulnerabilities were being exploited before public patches and CVE details were available. Citrix later confirmed exploitation and released the fixed builds.

What organizations should do now

Organizations running affected NetScaler systems should install the Citrix updates immediately. Systems exposed to the internet should receive the highest priority.

Administrators should also preserve logs and forensic evidence, review appliances for signs of compromise, rotate credentials and secrets that may have been accessible through the affected systems, and verify that management interfaces are not exposed unnecessarily.

A clean indicator-of-compromise check should not be treated as proof that a system was never accessed. Citrix customers should follow the vendor’s current security guidance and incident-response recommendations.

What remains unknown

Public reporting has not established the full number of organizations compromised or publicly attributed the attacks to a specific threat actor. Those details may change as incident-response investigations continue.

Sources

Citrix Security Bulletin CTX697096

watchTowr: Citrix NetScaler Zero-Day RCE FAQ

BleepingComputer: Citrix admins warned over exploited NetScaler zero-days

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment