www.securityweek.com 28 Sept 2026, 07:29 UTC

Citrix Patches NetScaler Zero Days Exploited in Global Attacks

Citrix Patches NetScaler Zero Days Exploited in Global Attacks
CyberSIXT Evidence Panel

CITRIX has released emergency patches for two critical NetScaler ADC and NetScaler Gateway zero-day vulnerabilities being exploited in the wild. The flaws are part of an advisory covering eight vulnerabilities, including remote code execution, HTTP request smuggling, denial-of-service and security-bypass issues. CVE-2026-88771 and CVE-2026-88772 both have a CVSS score of 9.5.

CVE-2026-88771 is an unauthenticated remote-code-execution flaw affecting all NetScaler ADC and Gateway deployments, including default configurations. CVE-2026-88772 is a memory-overflow vulnerability that can enable remote code execution or denial-of-service attacks on appliances with DTLS enabled, the default setting for VPN virtual servers.

Citrix has published indicators of compromise. The vulnerabilities were added to CISA’s Known Exploited Vulnerabilities catalogue, and the US agency warned that threat actors were actively exploiting them globally. CISA advised administrators to consult Citrix’s advisory and, where possible, check for compromise before applying patches. Reports from NetScaler administrators said IT suppliers, CERT teams and managed detection and response providers had urged them to shut down appliances over the weekend.

Some warnings reportedly originated from a private notification by the Dutch National Cyber Security Centre, which said exploitation had been identified at multiple Citrix customers worldwide. The article does not provide affected software versions or details of the exploitation techniques.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline