If you run a Citrix NetScaler box on the edge of your network, this weekend was a bad one. On Sunday, September 27, Citrix confirmed that attackers had already been exploiting two critical NetScaler vulnerabilities, before any patch existed.

The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, both score 9.5 out of 10 on the CVSS v4 severity scale. Either one lets an unauthenticated attacker run code remotely on a vulnerable appliance, with no user interaction needed. Citrix’s bulletin, CTX697096, put it plainly: “Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed.”

That was the first public notice of the flaws. There were no workarounds in the bulletin, and no indicators of compromise, just patches and an urgent plea to install them.

The two NetScaler zero-days, explained

CVE-2026-88771 is the worse of the pair in one specific way: it takes almost nothing to hit it. It’s an improper input validation bug that allows remote, unauthenticated attackers to execute arbitrary commands on the appliance, and it works against default configurations. No special feature needs to be enabled. If the box is reachable on the network and unpatched, it’s in play.

CVE-2026-88772 is a memory overflow flaw that can lead to remote code execution or denial of service. It needs DTLS enabled to be exploitable. But DTLS is turned on by default on VPN virtual servers, so most NetScaler Gateway deployments qualify without an admin ever touching the setting. The two bugs can be exploited independently of each other.

Citrix wouldn’t say how widespread the attacks are, who is behind them, or when they started. But this wasn’t a quiet disclosure. A day before the bulletin, the security firm watchTowr reported that two unpatched NetScaler RCE flaws were being actively exploited, and Dutch administrators began getting private warnings to act.

The Dutch shut their boxes off

The Dutch National Cyber Security Centre (NCSC-NL) didn’t wait for Citrix. Before patches existed, it told organizations in the Netherlands to shut down their NetScaler appliances immediately. Many did exactly that, pulling devices offline while security teams combed logs and core dumps for evidence attackers had already gotten in.

The agency’s warning was blunt: “This vulnerability gives attackers full control of the gateway, providing direct access to the internal corporate network behind it.”

That’s the part that makes NetScaler flaws so ugly. These appliances sit at the network edge handling VPN, remote access, load balancing, and authentication. Owning the gateway means owning the front door.

watchTowr, which flagged the exploitation first, wasn’t subtle either. “CVE-2026-88771 – the loaded Citrix footgun went off again,” the firm posted on September 28, linking its analysis of the bug.

CISA gives feds until Wednesday

The US government moved fast. CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 27, citing reports and partner intelligence confirming global exploitation. Federal agencies covered by the binding directive have until September 30 (this Wednesday) to remediate.

The bulletin patches six additional flaws too, numbered CVE-2026-88773 through CVE-2026-88778, covering HTTP request smuggling, policy bypass, more memory overflows, and TCP sequence-number prediction. But only the two zero-days are confirmed exploited in the wild.

Fixed builds are NetScaler ADC and Gateway 14.1-73.37 and later, plus 13.1-64.23 and later, with corresponding FIPS builds. Secure Private Access Hybrid deployments need the same upgrade. Citrix says its own managed cloud services and Adaptive Authentication were already updated.

Why this matters

Citrix has been here before — NetScaler zero-days in 2023 and 2025 were exploited at scale by ransomware crews and state-linked groups alike. Help Net Security’s analysis notes that roughly two-thirds of threat activity targeting NetScaler over the past seven years involved advanced persistent threat groups.

This time the pattern is familiar and alarming: credible exploitation warnings circulating privately for days, admins told to shut appliances down, then a Sunday emergency bulletin confirming the worst. If your team hasn’t patched yet, the clock isn’t theoretical. CISA’s federal deadline is September 30, and Citrix itself warns that patching doesn’t remove whatever attackers already planted. Treat this one as incident response, not routine maintenance.

Oh, and one telling detail from BleepingComputer: Citrix published its disclosure blog post with a “noindex” meta tag: telling search engines not to index the very announcement customers need to find.

FAQ

Which Citrix NetScaler zero-day vulnerabilities were exploited?

CVE-2026-88771, an improper input validation flaw allowing unauthenticated remote command execution, and CVE-2026-88772, a memory overflow enabling remote code execution or denial of service. Both scored 9.5 on CVSS v4, and Citrix confirmed September 27, 2026 that both were being exploited in the wild before patches existed.

How do I fix the NetScaler zero-day vulnerabilities?

Upgrade NetScaler ADC and Gateway to 14.1-73.37 or 13.1-64.23 (or later). Patching doesn’t remove backdoors attackers may have already installed, so check for signs of compromise (suspicious files in crash dump folders, unexpected admin accounts, unusual log entries) before or alongside updating.

What is the CISA deadline for patching NetScaler?

September 30, 2026. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 27 and ordered US federal agencies to remediate them by Wednesday. Private organizations should move at least that fast.

Who is at risk from the NetScaler zero-days?

Any organization running customer-managed NetScaler ADC or Gateway appliances. CVE-2026-88771 hits even default configurations; CVE-2026-88772 hits systems with DTLS enabled (the default for VPN virtual servers). Only self-managed appliances are affected. Citrix’s managed cloud services were already updated.

Sources: BleepingComputer, Help Net Security, The Cyber Express, SOCRadar, Citrix (bulletin CTX697096), CISA, NCSC-NL, watchTowr.