Citrix Patches Actively Exploited NetScaler Zero-Days

Citrix Patches Actively Exploited NetScaler Zero-Days

Two critical NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) allowing remote code execution are under active attack; patches are now available.

Citrix has confirmed that two critical remote code execution (RCE) vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances are being actively attacked and has released security updates to fix the flaws, designated CVE-2026-88771 and CVE-2026-88772.

The first vulnerability, CVE-2026-88771, is caused by improper input validation and allows an unauthenticated attacker to execute arbitrary commands on the device. It carries the maximum severity score of 9.5 out of 10. According to Citrix, this flaw affects all NetScaler ADC and NetScaler Gateway deployments, even those running in default configurations, and does not require any additional features to be switched on.

The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or a denial-of-service condition. It also has a severity score of 9.5. Exploitation is possible when DTLS, a protocol that provides secure communication for real-time services, is enabled. Citrix notes that DTLS is enabled by default on VPN virtual servers, meaning many installations are potentially exposed.

Citrix stated in its security bulletin CTX697096 that "exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." The affected versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, as well as certain FIPS and NDcPP builds. In total, the update addresses eight vulnerabilities, including the two zero-days.

Warnings about the exploitation began circulating over the weekend, well before Citrix made its public announcement. Administrators on Reddit reported being contacted by IT suppliers, security teams, law enforcement, and national cybersecurity agencies with urgent instructions to shut down their NetScaler appliances immediately. One administrator wrote that their supplier advised shutting the devices down "immediately" without providing further details.

Cybersecurity firm watchTowr later confirmed the credibility of the rumors, saying it was "rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild." The Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands, warning that two vulnerabilities could independently lead to remote code execution. The notification, seen by multiple sources, indicated that Citrix discovered the flaws while investigating incidents in customer environments and had submitted a notification under the European Union's Cyber Resilience Act.

The early warnings were intended to give organizations time to prepare, implement safeguards, and install patches as soon as they became available, since applying NetScaler upgrades can cause downtime. The NCSC also warned that exploitation attempts could increase once patches and technical details were released, and that exploitation had already been identified at multiple Citrix customers worldwide.

For organizations that manage their own NetScaler appliances, the only secure path forward is to upgrade to the patched builds immediately. Those unable to patch right away should limit Internet exposure of the devices wherever operationally feasible. Because NetScaler appliances often sit at the edge of a network providing remote access, a compromise can give attackers a direct foothold into internal corporate systems. For businesses without in-house security expertise to assess edge-device risks, consulting a security-focused IT partner like AEU-I can provide the guidance needed to identify and remediate such vulnerabilities before they are exploited.

Come Proteggerti

  1. If your organization uses Citrix NetScaler ADCs or Gateways, immediately apply the latest update from Citrix.
  2. If you cannot patch right away, remove the device from the public internet or block access from untrusted networks until the update is installed.
  3. Ask your IT provider or hosting company whether they manage any NetScaler appliances for you and confirm they have deployed the patch.
  4. Watch the device’s logs for any unexpected commands or unusual traffic patterns that might indicate a past compromise.
  5. Keep a current inventory of all Internet-facing network devices so you can quickly identify which ones need patching when critical updates like this are announced.

Vulnerabilità e Soluzioni

I Termini Spiegati

  • Remote code execution (RCE) A type of security flaw that lets an attacker run commands or programs on a device from afar, often taking full control of it.
  • Zero-day A vulnerability that is already being exploited by attackers before the software maker has released a fix.
  • DTLS A protocol that encrypts real-time data transmissions, similar to TLS, but designed for services like voice and video that need low latency.
  • NetScaler ADC A Citrix appliance that manages and optimizes the delivery of applications across networks, often placed at the edge of a corporate network.
  • NetScaler Gateway A Citrix device providing secure remote access for users to internal applications and desktops, typically reachable over the internet.
  • CERT Computer Emergency Response Team; a group of experts that coordinates responses to major cybersecurity incidents within a country or organization.

Servizi AEU correlati