Skip to content

Citrix patches two NetScaler zero-days already under attack

CVE-2026-88771 and CVE-2026-88772 let an unauthenticated attacker run arbitrary commands on NetScaler ADC and Gateway. Both are on the CISA exploited list as of 27 September.

Source: Citrix

Citrix published a security bulletin on 27 September covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which were already being exploited as zero-days before the patch existed.

CVE-2026-88771 (CVSS 9.5) is an improper input validation bug that lets an unauthenticated attacker run arbitrary commands, and it affects every NetScaler deployment on a vulnerable version in its default configuration, no feature flag required. CVE-2026-88772 (CVSS 9.5) is a memory overflow that also leads to RCE, but only where DTLS is enabled. Versions before 14.1-73.37 and before 13.1-64.23 are affected; both are fixed in those releases and later. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue the same day, confirming active exploitation, and is telling administrators to check for indicators of compromise before patching, since the update can wipe forensic evidence of a prior break-in.

Why it matters: NetScaler sits at the network edge in front of whatever you’re running, so an unauthenticated RCE there bypasses every application-layer control behind it. If you manage a NetScaler ADC or Gateway, this isn’t a maintenance-window patch, it’s a today patch, and it’s worth checking logs for compromise first rather than patching straight over the evidence.

The caveat: Citrix’s bulletin covers six other, lower-severity CVEs in the same release. Only 88771 and 88772 are confirmed exploited so far, but the advice to update applies to all eight.

Share

More from The Wire

All briefs