Citrix confirms two NetScaler zero-days, admins pull appliances

Citrix confirmed two NetScaler zero-day vulnerabilities are being exploited; administrators disconnected appliances while Citrix issued patches, indicators and a technical advisory over the weekend.

Over the weekend Citrix confirmed two NetScaler zero-day vulnerabilities are being exploited in the wild and published patches and a security advisory covering eight flaws affecting NetScaler ADC and NetScaler Gateway appliances.

The exploited vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772, each assigned a CVSS score of 9.5. CVE-2026-88771 is an unauthenticated remote code execution flaw that affects all NetScaler ADC and Gateway deployments, including default configurations. CVE-2026-88772 is a memory overflow that can be used to achieve remote code execution or to cause a denial of service on appliances with Datagram TLS (DTLS) enabled; Citrix notes DTLS is enabled by default on VPN virtual servers.

Citrix released software updates, technical details and indicators of compromise for administrators to review and to use for detection and response. The advisory also lists other issues, including HTTP request smuggling, denial-of-service and security bypass vulnerabilities, for a total of eight reported flaws.

System administrators reported receiving instructions from vendors, internal CERT teams and managed detection and response providers to disconnect NetScaler appliances, sometimes without additional explanation. Several of those notifications were linked to a private pre-notification from the Dutch National Cyber Security Centre distributed under TLP:AMBER, which referenced a European partner CERT and noted exploitation had been observed at multiple Citrix customers worldwide.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog and issued an alert warning that “threat actors are actively exploiting these vulnerabilities globally.” CISA’s KEV catalog also includes other recent NetScaler entries, including CVE-2026-19490 and CVE-2026-8452.

Administrators are being urged to apply Citrix updates, confirm whether DTLS is enabled on VPN virtual servers and use the published IoCs and appliance logs to check for signs of intrusion before and after patching. Monitoring and incident response teams are examining affected systems and networks to assess exposure and remediate any compromise.

Articles by this author