News

Citrix Confirms Attackers Used Two NetScaler Zero-Days While Admins Waited for Patches

Citrix confirms CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5, were exploited on NetScaler ADC and Gateway before patches. August builds are still vulnerable.

Citrix Confirms Attackers Used Two NetScaler Zero-Days While Admins Waited for Patches

Attackers were already inside NetScaler appliances before Citrix had a fix. The company has now confirmed that two critical flaws, CVE-2026-88771 and CVE-2026-88772, were exploited as zero-days on unmitigated NetScaler ADC and Gateway devices.

Both carry a CVSS score of 9.5. Citrix says it found them while investigating customer incidents, observed working exploits, and filed a notification under the EU Cyber Resilience Act.

A weekend of vague warnings

Admins got the first signal before any advisory existed. Over the weekend, IT suppliers, national CERTs and law enforcement privately told organizations to shut down their NetScalers, with almost no detail on why.

The Dutch NCSC sent a pre-notification citing a European partner CERT. Researchers at watchTowr called the rumors credible. For teams running remote access on these boxes, that meant choosing between an outage and an unknown risk.

Two bugs, both reachable by default

CVE-2026-88771 is an improper input validation flaw that allows unauthenticated remote code execution. It affects deployments in their default configuration, with no extra feature switched on.

CVE-2026-88772 is a memory overflow that can lead to code execution or denial of service when DTLS is enabled. DTLS is on by default for VPN virtual servers, which covers a large share of Gateway installs.

NetScaler sits at the network edge, handling VPN and application delivery. Owning one gives an attacker a foothold on the perimeter.

August patches are not enough

Citrix shipped fixes on September 27 in builds 14.1-73.37 and 13.1-64.23, plus FIPS and NDcPP versions. The same bulletin fixes six more flaws, eight in total.

The catch: the August builds that closed CVE-2026-19490, 14.1-73.32 and 13.1-63.21, are still vulnerable to both new bugs. These are different flaws from the August pair, so a box patched last month is exposed again. Citrix-managed cloud services are being upgraded by the vendor.

There is no public attribution to a named group, and nothing suggests every NetScaler was compromised. But Citrix says indicator-of-compromise scanning through NetScaler Console is still coming, which leaves defenders hunting for traces of an attack that started before anyone knew the bugs existed.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free