Security · September 30, 2026

Also published in Português (Brasil)

Citrix confirms active exploitation of two critical zero-day flaws in NetScaler appliances

person holding black phone
ROBIN WORRALL / Unsplash

Citrix has confirmed that two critical zero-day vulnerabilities in its NetScaler ADC and NetScaler Gateway products are being actively exploited. The company issued a security bulletin on September 27, 2026, detailing the flaws and providing guidance for affected organizations. The immediate directive to administrators was to shut down the appliances to prevent unauthorized access.

The vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, allow for remote code execution. Citrix stated that it identified these issues during investigations into incidents at its clients. The company reported observing exploitation of these specific flaws on unpatched NetScaler deployments. The security bulletin referenced a total of eight vulnerabilities, of which these two are currently being exploited in the wild. Both flaws carry a CVSS 4.0 score of 9.5 out of 10, indicating a critical severity level.

The urgency of the situation was highlighted by early warnings from security teams. Administrators reported receiving calls from their service providers or internal security teams with a single instruction: stop the NetScaler devices immediately. These warnings often lacked technical details. Some administrators mentioned contacts with Computer Emergency Response Teams. The initial panic reportedly stemmed from a pre-notification sent by the Dutch National Cyber Security Centre to organizations in the Netherlands. This agency described the two vulnerabilities as enabling remote code execution.

The United States Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalog on the same day the bulletin was published. The agency issued a dedicated alert stating it had received reports confirming active exploitation on a global scale. Citrix did not disclose the scale of the attacks or the identity of the actors responsible. The appliances are typically exposed to the internet to facilitate remote access to internal resources, making them a high-value target for attackers seeking network entry.

Organizations must apply specific security patches to mitigate the risk. The builds released in August to address the previous flaw, CVE-2026-19490, specifically versions 14.1-73.32 and 13.1-63.21, do not protect against these new vulnerabilities. Administrators who updated their systems last month must apply the new patches. The earlier August flaw was not being exploited at the time of its disclosure but has since been added to the Known Exploited Vulnerabilities catalog. This incident follows a series of critical security alerts for Citrix products, including the CitrixBleed 2 issue in June 2025 and the zero-day CVE-2025-7775 exploited in August 2025.