Vulnerability

Citrix confirms active exploitation of two NetScaler zero‑days

⏱️ 4 min read📅 9/28/2026👁️ 13 views

What’s happening

Citrix confirmed that two critical NetScaler zero‑days – CVE‑2026‑88771 and CVE‑2026‑88772 – are already being leveraged in real‑world attacks.

The company released bulletin CTX697096, which contains patches for NetScaler ADC and NetScaler Gateway.

Technical snapshot

CVE‑2026‑88771 is a remote code execution flaw rated 9.5 on the CVSS scale. CVE‑2026‑88772 is a memory overflow that also scores 9.5, but it only triggers when DTLS is enabled.

Both bugs affect NetScaler ADC and Gateway versions prior to 14.1‑73.37 (including 14.1‑73.37 FIPS), and the 13.1 line before 13.1‑64.23 (or 13.1‑37.279 for ADC FIPS and NDcPP).

Who’s at risk

Any organization running the listed NetScaler ADC, Gateway, ADC FIPS or NDcPP firmware is potentially exposed. The Dutch National Cyber Security Center (NCSC‑NL) sent a pre‑notification to Dutch entities, indicating that exploitation has been observed at multiple Citrix customers worldwide.

Immediate defensive steps

  1. Download and apply the CTX697096 patches without delay.
  2. If you cannot patch immediately, disable DTLS on affected appliances to mitigate CVE‑2026‑88772.
  3. Consider temporarily taking NetScaler ADC/Gateway instances offline while remediation is in progress.
  4. Monitor network traffic for unexpected outbound connections from NetScaler devices, especially to unknown IPs.
  5. Verify firmware versions against the affected‑versions list and document compliance.

Why it matters

Both vulnerabilities score near the top of the CVSS scale, meaning an attacker who reaches the vulnerable service can execute arbitrary code with system privileges. In the hands of a skilled actor, the impact ranges from data theft to full control of the internal network.

#Citrix#NetScaler#CVE-2026-88771#CVE-2026-88772#Zero-Day#Patch