CITRIX confirmed on 27 September 2026 that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway had been exploited against unmitigated systems before patches were available. The flaws are CVE-2026-88771 and CVE-2026-88772, both rated 9.5 by CVSS. Citrix has not disclosed how many organisations were affected, who carried out the attacks or when exploitation began.
Reports of the activity first circulated privately among administrators and security teams, while watchTowr said it was investigating credible reports of multiple unpatched NetScaler remote-code-execution flaws. The Dutch National Cyber Security Centre also issued a pre-notification to organisations in the Netherlands.
CVE-2026-88771 is an input-validation flaw that allows an unauthenticated attacker to execute arbitrary commands and affects affected versions without requiring an additional feature to be enabled. CVE-2026-88772 is a memory-overflow vulnerability that can enable remote code execution or denial of service on appliances with DTLS enabled; DTLS is enabled by default for VPN virtual servers in NetScaler Gateway unless administrators disable it.
Citrix released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, and 13.1-64.23 and later, with updates also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches. Builds 14.1-73.32 and 13.1-63.21, released for CVE-2026-19490, remain vulnerable to these newer flaws.
Citrix urged customers to install the relevant updates immediately and use its NetScaler Console indicators of compromise to check for possible compromise. The scans require telemetry and NetScaler Console service, or an on-premises deployment with Cloud Connect, and Citrix warns that the indicators may not detect every attacker technique.