Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Key Points:
- Citrix confirmed on September 27 that two critical remote code execution vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway have been exploited in the wild, affecting all deployments on certain versions including default configurations.
- The first flaw (CVE-2026-88771) allows unauthenticated attackers to run arbitrary commands, while the second (CVE-2026-88772) is a memory overflow impacting appliances with DTLS enabled, which is on by default for VPN virtual servers.
- Citrix released fixes for these two exploited flaws along with six other vulnerabilities and urged customers to update immediately to versions 14.1-73.37, 13.1-64.23, or later; no workarounds or indicators of compromise were provided.
- Exploitation was observed before patches were public, prompting some administrators to take NetScaler appliances offline; Citrix advised preserving evidence, isolating affected devices, changing passwords, and not exposing management interfaces to the internet.
- The vulnerabilities were first reported by security firm watchTowr, which discovered them during forensic investigations, and Citrix's bulletin is the first public acknowledgment; additional guidance and detection scripts from prior incidents remain relevant for mitigation.