Blog

Two Critical Citrix NetScaler Zero-Days Exploited in the Wild

Written by tortue974 - September 27, 2026

← All articles

Two Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler

Citrix has confirmed the active exploitation of two critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Both flaws can enable remote code execution and were exploited before a security patch became available.

The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, have both been assigned a CVSS v4 score of 9.5 out of 10.

The first vulnerability, CVE-2026-88771, is caused by improper input validation. It allows an unauthenticated attacker to execute commands remotely. Its scope is particularly concerning: all NetScaler ADC and NetScaler Gateway installations running a vulnerable version are affected, and exploitation does not require any specific feature to be enabled.

The second vulnerability, CVE-2026-88772, is related to a memory overflow that can lead to remote code execution or a denial-of-service condition. It affects appliances with DTLS enabled. This is particularly significant because DTLS is enabled by default for VPN virtual servers, potentially exposing NetScaler Gateway deployments.

Exploitation Has Already Been Observed

Citrix says it has observed exploitation of both vulnerabilities on appliances that had not yet been patched. However, the vendor has not disclosed how long the attacks have been ongoing, how widespread they are, or who may be behind them.

The confirmation follows an alert published on September 26 by cybersecurity company watchTowr, which reported several zero-day vulnerabilities affecting NetScaler that were being actively exploited in the wild. The technical details currently available are consistent with the two vulnerabilities now confirmed by Citrix, although the vendor has not explicitly stated that the issues reported by watchTowr were the same vulnerabilities.

Some administrators have also reported receiving recommendations from their security providers to take NetScaler appliances offline as a precaution.

Patches Are Available

Citrix has released updates addressing the two actively exploited vulnerabilities, along with six additional security flaws.

The patched versions include:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later

  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later

  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later

  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later

Citrix recommends that affected organizations apply these updates as soon as possible.

It is worth noting that versions 14.1-73.32 and 13.1-63.21, which had previously addressed a critical vulnerability exploited in August, remain vulnerable to the newly disclosed flaws.

Six Additional Vulnerabilities Addressed

The security bulletin also addresses six additional vulnerabilities that have not been reported as actively exploited at this time.

These include a HTTP request smuggling vulnerability rated 9.3, several memory overflow vulnerabilities rated 8.8, as well as a policy bypass flaw and a vulnerability related to TCP sequence number prediction.

The issues affect various NetScaler configurations, including environments using load balancing, VPN services, authentication, and certain network protocols.

Patching Alone May Not Be Enough

For organizations that were already exposed, the most important consideration is that simply installing the security update does not, by itself, determine whether an appliance was compromised before the patch became available.

If an intrusion is suspected, Citrix recommends preserving the evidence required for forensic analysis, isolating the affected appliance, and rotating credentials and secrets that may have been exposed.

Service accounts, passwords belonging to users whose credentials passed through the appliance, as well as associated certificates and private keys, should all be considered potentially compromised.

Citrix also reiterates that the NetScaler administrative interface should never be directly exposed to the Internet.

A Situation Requiring Immediate Verification

These two vulnerabilities pose a particularly significant risk because of NetScaler's position within enterprise environments. NetScaler appliances are typically deployed at the network perimeter and provide critical services such as remote access, VPN connectivity, authentication, and load balancing.

For organizations running vulnerable versions, the priority is therefore twofold: deploy the patched versions and investigate for any evidence of prior exploitation.

If an exposed appliance may have been compromised, simply applying the update should not be considered sufficient. Reviewing logs, system images, and other available forensic evidence may be necessary to determine whether an attacker had already gained access before the security patch was deployed.

Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.