Citrix NetScaler Zero-Days Actively Exploited: Urgent Patches Released
Two critical remote code execution vulnerabilities in **Citrix NetScaler ADC** and **NetScaler Gateway** appliances, tracked as **CVE-2026-88771** and **CVE-2026-88772**, are being actively exploited in the wild. **Citrix** has confirmed the zero-day attacks and released urgent security updates, urging IT security professionals and privacy-conscious users to patch their systems immediately.

**Citrix** has officially confirmed active exploitation of two critical remote code execution (RCE) vulnerabilities, **CVE-2026-88771** and **CVE-2026-88772**, affecting its **NetScaler ADC** and **NetScaler Gateway** products. The company has released security updates to address these flaws, which were initially circulated as private warnings among cybersecurity researchers and national agencies.
## Why NetScaler Appliances Are Prime Targets
**NetScaler** appliances are highly attractive targets for attackers due to their common deployment as internet-facing edge devices. They provide crucial remote access and application delivery services for internal corporate networks. A successful compromise of these devices can offer attackers an initial foothold at the network perimeter, potentially paving the way to internal systems without needing to breach an endpoint within the organization.
## Early Warnings and Community Buzz
The first signs of these zero-days emerged over the weekend when **Citrix** administrators reported on Reddit that IT suppliers and security teams were privately contacting their organizations, advising them to shut down their **NetScaler** appliances immediately. One administrator recounted, "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our **Netscalers** down immediately."
Other reports indicated that law enforcement, CERTs, and national cybersecurity agencies were also reaching out to organizations. Cybersecurity firm **watchTowr** later issued a public warning, confirming rumors of multiple unpatched **Citrix NetScaler** RCE vulnerabilities being exploited after verifying the information with authoritative sources.
## Citrix Confirms Active Exploitation and Releases Patches
**Citrix** has since published security bulletin **CTX697096**, officially confirming the vulnerabilities and releasing patches for affected **NetScaler ADC** and **NetScaler Gateway** appliances.
**CVE-2026-88771** is an RCE vulnerability stemming from improper input validation, allowing an unauthenticated attacker to execute arbitrary commands. It carries a high severity score of 9.5. This flaw affects all **NetScaler ADC** and **NetScaler Gateway** deployments, including those with default configurations, and does not require any specific feature to be enabled.
**CVE-2026-88772** is a memory overflow vulnerability that can lead to remote code execution or a denial-of-service (DoS) condition, also rated with a severity score of 9.5. This vulnerability is exploitable when DTLS is enabled on a **NetScaler ADC** or **NetScaler Gateway**. **Citrix** notes that DTLS is enabled by default on VPN virtual servers.
**Citrix** explicitly stated, "Exploits of **CVE-2026-88771** and **CVE-2026-88772** on unmitigated **NetScaler** deployments have been observed."
Affected versions include:
* **NetScaler ADC** and **NetScaler Gateway** 14.1 before 14.1-73.37
* **NetScaler ADC** and **NetScaler Gateway** 13.1 before 13.1-64.23
* **NetScaler ADC FIPS** before 14.1-73.37 FIPS
* **NetScaler ADC FIPS** and **NDcPP** before 13.1-37.279
**Secure Private Access Hybrid** deployments utilizing **NetScaler** instances are also affected and require upgrades to the recommended builds. The bulletin applies solely to customer-managed **NetScaler ADC** and **NetScaler Gateway** appliances, with **Cloud Software Group** handling upgrades for **Citrix**-managed cloud services and **Adaptive Authentication**.
In total, this update addresses eight **NetScaler** vulnerabilities, including the two critical zero-days.
## Pre-Disclosure Warnings from NCSC-NL
Prior to **Citrix**'s public disclosure, the **Dutch National Cyber Security Center (NCSC-NL)** reportedly issued a pre-notification to organizations in the Netherlands, warning about two critical **NetScaler** zero-days. Shared copies of the notification indicated that the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution.
The **NCSC-NL** notice mentioned one vulnerability allowed attackers to directly place shellcode into memory, while technical details for the second were still under investigation. At that time, no **CVE** identifiers had been assigned, and **Citrix** had not yet published an advisory.
According to the notification, **Citrix** discovered these vulnerabilities while investigating incidents in customer environments and identified active exploitation. It also stated that **Citrix** submitted a notification under the **European Union's Cyber Resilience Act** after detecting the attacks.
The **NCSC-NL** confirmed exploitation at multiple **Citrix** customer sites globally but could not ascertain the widespread nature of the attacks. The agency also cautioned that exploitation attempts could escalate once **Citrix** released patches and additional technical details.
Given that **NetScaler** upgrades can cause downtime, the **NCSC-NL**'s warning aimed to provide organizations with time to prepare, implement safeguards where feasible, and rapidly install patches upon availability.
## Immediate Action Required
Now that **Citrix** has released fixes and confirmed active exploitation, administrators must upgrade affected **NetScaler ADC** and **NetScaler Gateway** appliances to the patched versions as quickly as possible. Organizations unable to apply updates immediately should reduce internet exposure where operationally viable until they can patch their appliances.