Citrix patches two NetScaler zero-days exploited in the wild for unauthenticated RCE

· CyberSecurity

TLDR

  • Citrix has patched two zero-day flaws in NetScaler ADC and Gateway, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, that were already being exploited in the wild before the fix shipped.
  • CVE-2026-88771 is an unauthenticated remote-code-execution flaw affecting all NetScaler ADC and Gateway deployments by default; CVE-2026-88772 is a memory-overflow bug affecting deployments with DTLS enabled, which is Gateway's default.
  • Citrix confirmed exploitation of "unmitigated NetScaler deployments" without disclosing scale, attacker identity, or a start date; security firm watchTowr and the Dutch NCSC had flagged rumours of the unpatched bugs a day before the public fix.
  • The patch bundle also closes six unexploited flaws; appliances that already patched August's CVE-2026-19490 authentication-bypass bug remain in the vulnerable range and need this update too.

Citrix released security bulletin CTX697096, patching CVE-2026-88771 and CVE-2026-88772, both rated CVSS 9.5.1 CVE-2026-88771 is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands, and affects all NetScaler ADC and Gateway deployments regardless of configuration.1 CVE-2026-88772 is a memory overflow bug that can cause remote code execution or denial of service on appliances with DTLS enabled, which is on by default for VPN virtual servers.1 Citrix confirmed active exploitation, stating "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed."1

On 26 September, before the patch was released, security firm watchTowr said it was responding to "credible" rumours of unpatched NetScaler remote-code-execution flaws that it had learned of during forensic investigations, and Reddit users reported IT suppliers warning them to shut down NetScaler appliances immediately.1 The Dutch National Cyber Security Centre had separately received a pre-notification about the flaws from an unnamed European partner CERT, and Citrix reportedly filed a notice under the EU's Cyber Resilience Act after detecting the attacks.2 Citrix has not disclosed how many organisations were affected, though the Dutch agency said exploitation had reportedly hit "multiple Citrix customers worldwide."2

The patch bundle also fixes six additional, unexploited vulnerabilities, and applies to NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, along with the FIPS and NDcPP variants.1 Builds that already patched August's CVE-2026-19490 authentication-bypass flaw remain in the vulnerable range and need this update too, and the 13.1 branch received a fix despite reaching end of maintenance on 15 September.1

Why it matters: two unauthenticated, CVSS 9.5 remote-code-execution paths into internet-facing VPN and load-balancing appliances were exploited before any patch existed, and since patching does not remove access attackers may have already gained, organisations running NetScaler need to treat this as a possible-compromise event, not just a routine update.

Sources

  1. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation (The Hacker News)
  2. Citrix admins warned to shut down NetScalers over 2 exploited zero-days (BleepingComputer)