Citrix Confirms Two NetScaler RCE Zero-Days Under Attack
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities are being actively exploited in attacks, prompting the release of immediate security updates for affected deployments.

Citrix Confirms Active Zero-Day Exploitation
Citrix has officially confirmed that two critical NetScaler remote code execution vulnerabilities are being actively exploited in the wild as zero-days. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were addressed after cybersecurity researchers, IT suppliers, and national security agencies privately warned organizations about suspicious activity over the weekend.
NetScaler appliances are prime targets for malicious actors because they are typically deployed as Internet-facing edge devices. These devices provide remote access and application delivery services for corporate networks, meaning a successful compromise gives attackers an immediate perimeter foothold.
Early Warnings and Industry Alerts
The first indications of the incident surfaced when Citrix administrators reported on social platforms that IT suppliers and security teams were urgently contacting organizations. In one instance, one administrator wrote about receiving an urgent phone call advising them to shut down their NetScaler appliances immediately without receiving full initial details.
Shortly after initial reports spread, cybersecurity firm watchTowr said that it was actively reacting to circulating rumors regarding unpatched remote code execution vulnerabilities after verifying the information through authoritative sources.
Details of the Vulnerabilities
Following the reports, Citrix published security bulletin CTX697096 to detail the flaws and provide corrective software builds for NetScaler ADC and NetScaler Gateway deployments.
CVE-2026-88771 stems from improper input validation, allowing unauthenticated attackers to execute arbitrary commands with a severity score of 9.5. Citrix notes that this vulnerability affects all deployments, even those using default configurations without requiring extra features to be enabled.
The second flaw, CVE-2026-88772, is a memory overflow vulnerability carrying a 9.5 severity score that can lead to remote code execution or denial-of-service conditions. This issue can be exploited when DTLS is enabled, which Citrix points out is active by default on VPN virtual servers.
Affected Versions and Remediation
According to the security bulletin, customer-managed NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.37, versions 13.1 before 13.1-64.23, and NetScaler ADC FIPS and NDcPP deployments prior to 13.1-37.279 are impacted. Secure Private Access Hybrid deployments utilizing NetScaler instances also require immediate upgrading.
Organizations managing these appliances are urged to consult the official security bulletin for comprehensive instructions. Administrators unable to apply patches immediately should reduce Internet exposure where operationally feasible until updates can be safely installed.
Sources
- BleepingComputerCitrix confirms two NetScaler RCE zero-days exploited in attacks