Citrix Confirms Critical NetScaler Zero-Day Exploits, Urges Immediate Patches
Software vendor Citrix has officially confirmed that two critical remote code execution zero-day vulnerabilities affecting its NetScaler products are currently being exploited in active cyberattacks. The company has published security updates to address the flaws, which have drawn urgent warnings from cybersecurity researchers, IT infrastructure providers, and national cybersecurity agencies worldwide.
The vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, each carry a severe CVSS score of 9.5. NetScaler appliances represent high-value targets for malicious actors because corporate environments routinely deploy them as Internet-facing edge devices. These appliances manage vital remote access and application delivery services for internal corporate networks, meaning a successful perimeter compromise can grant unauthorized entities an initial foothold and a potential pathway into internal systems.
Details of the Exploit and Affected Systems
According to the official security advisory issued by Citrix, the identified vulnerabilities stem from distinct technical weaknesses within the software architecture:
- CVE-2026-88771: A remote code execution flaw resulting from improper input validation. This vulnerability enables unauthenticated attackers to execute arbitrary commands and affects all NetScaler ADC and NetScaler Gateway deployments, including standard configurations without optional features enabled.
- CVE-2026-88772: A memory overflow vulnerability capable of inducing remote code execution or triggering a denial-of-service condition. This issue occurs when Datagram Transport Layer Security (DTLS) is enabled—a setting active by default on VPN virtual servers.
Citrix has verified that exploits targeting both vulnerabilities on unmitigated NetScaler deployments have been observed in the wild. Customer-managed NetScaler ADC and NetScaler Gateway appliances running versions prior to the newly released builds are considered vulnerable. This includes specific iterations of NetScaler ADC and NetScaler Gateway version 14.1 and 13.1, alongside specialized FIPS and NDcPP deployments. Hybrid Secure Private Access deployments utilizing NetScaler instances also require immediate upgrades.
Early Warnings and Regulatory Notifications
Prior to the public disclosure by Citrix, informal alerts circulated across administrator forums as IT suppliers and security teams privately contacted corporate clients, advising them to temporarily shut down their NetScaler infrastructure. Concurrently, the Dutch National Cyber Security Center (NCSC-NL) issued a pre-notification to organizations within its jurisdiction, warning of two critical zero-days capable of independent remote code execution.
The NCSC-NL advisory noted that Citrix discovered the vulnerabilities while investigating security incidents within customer environments and subsequently filed a notification under the European Union’s Cyber Resilience Act. Although the agency could not verify the full geographic spread of the incidents, it confirmed that exploitation had been identified across multiple international customers.
Recommended Mitigation Steps
Security professionals and network administrators are strongly urged to apply the latest patches provided by Citrix immediately. For organizations unable to execute software updates without causing operational disruption, security experts recommend mitigating risk by strictly reducing Internet exposure of vulnerable appliances until the necessary firmware upgrades can be successfully deployed.
Source: BleepingComputer