TL;DR
Two Citrix NetScaler zero-day flaws allowing remote code execution have been exploited in the wild. The alert began with a leaked NCSC-NL pre-notification and was echoed by watchTowr and Kevin Beaumont. Citrix has now released a security bulletin covering eight CVEs, and it confirms exploitation of CVE-2026-88771 and CVE-2026-88772. Patch now.
CISA KEV isn't the only exploit signal for Citrix CVEs. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy This NetScaler Zero-Day Matters
NetScaler ADC and Gateway sit at the network edge. They terminate VPN sessions, balance application traffic, and authenticate users before they reach internal systems. A pre-authentication remote code execution flaw on that tier is severe. When the front door falls, an attacker gains a foothold with no credentials.
History sharpens the concern. NetScaler has been a repeat target, with 13 NetScaler-related entries in CISA’s Known Exploited Vulnerabilities catalog. This time, though, the reported exploitation appears to have started before any patch existed.
How the Alert Surfaced
The story did not begin with a vendor bulletin. Instead, it started in the community. On September 25, 2026, a post on the r/Citrix subreddit relayed urgent advice to shut down NetScaler devices. That advice reportedly traced to a Dutch NCSC-NL pre-notification shared under strict TLP:AMBER+STRICT handling. You can read the community thread that first raised the alarm in this r/Citrix discussion of the NetScaler leak.
The next day, researchers went public. watchTowr said it was reacting to credible reports of unpatched NetScaler RCE flaws, and later described them as two distinct zero-day vulnerabilities. The firm shared its warning in a watchTowr advisory post on X. Kevin Beaumont separately said the zero-day activity was real and tied to active attacks.
What Is Actually Confirmed
Precise technical details remain scarce, and that matters. According to watchTowr, the flaws enable remote code execution on internet-facing NetScaler ADC and Gateway appliances. The firm also said it identified the activity during forensic work on compromised customer environments. In other words, attackers were reportedly using the flaws before defenders knew they existed.
Before the bulletin landed, several points stayed unconfirmed. No CVE identifiers had been assigned. No public proof-of-concept existed. No indicators of compromise had been released. That early uncertainty is why deep root-cause writeups circulating at the time deserved caution. Citrix has since assigned CVE numbers and shipped fixes, covered in the update below.
Not the Same as CVE-2026-19490
One clarification is important. These reported zero-day flaws are not CVE-2026-19490 or CVE-2026-19489. Those are earlier NetScaler issues that already have fixes. CVE-2026-19490, an authentication bypass, was patched on August 19 and added to CISA’s KEV catalog on September 9. watchTowr specifically warned against confusing the two.
What Defenders Should Do Now
With no patch available, containment is the priority. Security teams should act on sourced, sensible guidance rather than wait.
- Restrict inbound access: Limit TCP 443 on Gateway interfaces to trusted, corporate IP ranges. Remove open 0.0.0.0/0 exposure where possible.
- Consider taking it offline: If NetScaler Gateway serves only remote or admin access, some administrators have chosen to shut exposed appliances down until a patch lands.
- Disable unused endpoints: If the device only does load balancing, confirm the VPN virtual server is disabled.
- Hunt and preserve evidence: Because exploitation reportedly preceded any fix, patching later will not prove an appliance is clean. Watch for unexpected processes, unusual crash dumps, and new files in web directories, and image any suspect appliance before wiping.
Update: Citrix Releases a Security Bulletin
Citrix has now published a formal advisory. The bulletin covers eight flaws, tracked as CVE-2026-88771 through CVE-2026-88778. Two of them are the actively attacked issues. Citrix states in its NetScaler ADC and NetScaler Gateway security bulletin: “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.”
The advisory confirms the scope is broad. As Citrix puts it, “all NetScaler ADC and NetScaler Gateway are impacted by one or more of the vulnerabilities.” The vendor recommends “upgrading the versions containing the fix immediately.”
The Two Exploited Flaws
CVE-2026-88771 is the most dangerous of the set. It carries a CVSS v4.0 score of 9.5. Citrix describes it as “remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.” Crucially, it affects “all NetScaler ADC and NetScaler Gateway deployments, including default configuration.” No special feature needs to be enabled.
CVE-2026-88772 also scores 9.5. It is a memory overflow that can lead to remote code execution or denial of service. However, it applies only when DTLS is enabled. Citrix notes that “DTLS is enabled by default on VPN virtual servers,” so many Gateway deployments meet that precondition.
Fixed Versions
Citrix lists the builds that contain the fix. Customers should move to one of these releases, or a later build in the same branch.
- NetScaler ADC and NetScaler Gateway 14.1-73.37 and later
- NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later
The other six CVEs range from HTTP request smuggling (CVE-2026-88773, CVSS 9.3) to a TCP sequence-number prediction issue (CVE-2026-88778, CVSS 8.8). Their impact depends on which features a deployment has enabled.
Citrix is also providing generic Indicators of Compromise through NetScaler Console. Still, the vendor warns that “the IoC Information might be of limited forensic value and might fail to identify actual compromises.” So patching alone is not proof of safety. Because the exploited flaws hit unmitigated appliances before a fix existed, defenders should hunt for compromise and treat any exposed appliance as suspect until reviewed.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!