Back to News
News · Cybersecurity

Two Citrix NetScaler Zero-Days Under Active Exploitation

Citrix has confirmed attackers exploited two critical NetScaler flaws before patches existed, prompting private warnings to shut appliances down over the weekend.

Source: BleepingComputer · September 27, 2026

Citrix has confirmed that two critical NetScaler ADC and NetScaler Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, were exploited in attacks as zero-days, and has released patches for both. CVE-2026-88771 (CVSS 9.5) is an improper input validation flaw that lets an unauthenticated attacker run arbitrary commands, affecting every deployment on an affected version, including default configurations. CVE-2026-88772 (also CVSS 9.5) is a memory overflow flaw that can lead to remote code execution or a denial-of-service condition, exploitable when DTLS is enabled, which it is by default on VPN virtual servers.

According to BleepingComputer, security researchers, IT providers and national cybersecurity agencies had privately warned organizations to shut their NetScaler appliances down over the weekend, before Citrix's public confirmation, with one administrator reporting a call from their IT supplier's security team advising an immediate shutdown. Citrix has since published security bulletin CTX697096 with the fixes. NetScaler appliances are commonly deployed as internet-facing edge devices, making them high-value targets for attackers seeking an initial foothold into internal corporate networks.

Why it matters: edge and perimeter infrastructure remains one of the most targeted layers in enterprise environments, and exploitation ahead of a patch means rapid response, network segmentation and continuous monitoring of internet-facing systems are essential, part of what we operate for clients.