Citrix confirms two NetScaler zero-days under active attack, ships emergency fixes
Citrix patched eight NetScaler ADC and Gateway flaws, two of them already exploited; CISA gave federal agencies until September 30 to act.
By Tech CEO Daily Staff, Newsroom
· 2 min read

The news
Citrix on September 27 published a security bulletin covering eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the remote-access and load-balancing appliances that sit at the internet edge of many corporate networks. The company said it has observed exploitation of two of them, CVE-2026-88771 and CVE-2026-88772, on unmitigated devices.
Both carry a CVSS score of 9.5. According to Citrix, CVE-2026-88771 stems from improper input validation, allows remote code execution and affects deployments in their default configuration. CVE-2026-88772 is a memory overflow that can lead to code execution or denial of service and requires DTLS, which Citrix notes is enabled by default on VPN virtual servers. The remaining six bugs range from 7.0 to 9.3 in severity.
Fixed builds are 14.1-73.37 and 13.1-64.23 or later, plus corresponding FIPS releases. CISA added both exploited flaws to its Known Exploited Vulnerabilities catalog the same day, and BleepingComputer reported that federal civilian agencies must remediate by September 30.
The attacks appear to predate the patch. Help Net Security cited researcher Kevin Beaumont as saying European government sources had warned organisations all week and that activity had been unfolding for the month. BleepingComputer reported that some administrators were told by suppliers and national CERTs, including the Dutch NCSC, to take appliances offline before Citrix confirmed the issue, and that attackers planted webshells on compromised devices. BleepingComputer also reported more than 23,000 internet-exposed NetScaler IP addresses.
The numbers
- CVSS (both exploited flaws)
- 9.5
- Vulnerabilities patched
- 8
- Federal patch deadline
- Sept 30, 2026
- Exposed NetScaler IPs (per BleepingComputer)
- 23,000+
Why CEOs should care
NetScaler often fronts VPN and single sign-on access, so a compromise here can become a foothold in the wider network. Ask your security team three things today: do we run NetScaler, directly or through a managed service provider; are all appliances on the fixed builds; and did we check for compromise before patching? CISA advises capturing forensic evidence first, because upgrading can erase traces, and the Dutch NCSC recommended preserving at least a month of memory and logs.
Patching alone does not remove an intruder who got in earlier. If webshells or suspicious activity turn up, treat it as an incident: engage forensic responders, rotate credentials that passed through the device, and review whether breach-notification or SEC materiality assessments are triggered.
The bigger picture
Edge devices remain attackers’ favourite doorway. BleepingComputer counts 26 actively exploited Citrix flaws flagged by CISA since November 2021, six of them used by ransomware groups, and older NetScaler versions 12.1 and 13.0 are end-of-life and will not receive fixes.
What's next
Expect more indicators of compromise and possibly victim disclosures in the coming days. Citrix has published separate compromise-assessment guidance (CTX694799), and CISA says indicators are available through NetScaler Console.
Sources
- PrimaryCitrix NetScaler ADC and NetScaler Gateway Security Bulletin (CTX697096)— Citrix
- GovernmentCritical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway— CISA
- GovernmentCISA Adds Two Known Exploited Vulnerabilities to Catalog— CISA
- ReportCitrix confirms two NetScaler RCE zero-days exploited in attacks— BleepingComputer
- ReportCISA orders feds to patch exploited Citrix flaws by Wednesday— BleepingComputer
- ReportCitrix NetScaler RCE zero-days exploited globally for weeks— Help Net Security
Newsroom
Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.
Spotted an error? Request a correction. Read our editorial standards and AI policy.
The Daily Brief
The technology briefing for people running businesses.
Weekdays at 6 a.m. ET. Free.


