Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Swati KhandelwalSep 27, 2026Vulnerability / Network Security

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration.

The bulletin came a day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited, and after some administrators said they had taken appliances offline. Citrix did not say whether its two flaws are the ones watchTowr described, but they match that account.

NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.

Citrix said in its bulletin that the two exploited flaws are:

  • CVE-2026-88771 (CVSS v4 score: 9.5) – An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments, with no extra feature required.
  • CVE-2026-88772 (CVSS v4 score: 9.5) – A memory overflow that can lead to remote code execution or denial-of-service (DoS). It affects appliances with DTLS enabled. DTLS is on by default for VPN virtual servers, so a NetScaler Gateway is affected unless DTLS has been explicitly turned off.

“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” the company said. It did not say how widely the flaws have been exploited, by whom, or since when.

The bulletin is Citrix’s first public notice of the flaws, so both were attacked before a fix was public. It lists no workaround for either and no indicators of compromise.

Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the exploited authentication bypass CVE-2026-19490 in August, fall inside the affected range and need the new update.

The fixes are in the following versions, which Citrix urged affected customers to install as soon as possible:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments. Citrix upgrades its own cloud services and Citrix-managed Adaptive Authentication.

The 13.1 fix arrives after that branch reached End of Maintenance on September 15 under Citrix’s release schedule.

The six other flaws, which the bulletin does not list as exploited, are:

  • CVE-2026-88773 (CVSS v4 score: 9.3) – An HTTP request smuggling flaw, on appliances with load balancing, content switching, VPN, or authentication virtual servers of type HTTP or SSL.
  • CVE-2026-88774 (CVSS v4 score: 7.0) – A policy bypass, on appliances where any policy uses an HTTP URL-based expression.
  • CVE-2026-88775 (CVSS v4 score: 8.8) – A memory overflow that can cause unpredictable behavior or DoS, on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an authentication, authorization, and auditing (AAA) virtual server.
  • CVE-2026-88776 (CVSS v4 score: 8.8) – A memory overflow that can cause unpredictable behavior or DoS, on load balancing virtual servers of type Oracle.
  • CVE-2026-88777 (CVSS v4 score: 8.8) – A memory overflow that can cause unpredictable behavior or DoS, on load balancing, content switching, or CGNAT-LSN/NAT64 setups with a non-HTTP Layer 7 protocol feature, such as FTP, RTSP, or DNS64, enabled.
  • CVE-2026-88778 (CVSS v4 score: 8.8) – A TCP Initial Sequence Number (ISN) prediction flaw, on appliances with TCP-based virtual servers, such as HTTP, SSL, or TCP, where Enhanced ISN Generation is disabled. Citrix advises affected appliances to apply a TCP configuration change that turns it on.

watchTowr’s first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild. “While details are scarce, the information is credible,” it wrote. A follow-up post at 22:19 UTC said the two flaws were discovered during forensic investigations and that Citrix communications and patches were expected early in the week of September 28.

On September 26, an administrator posting on r/Citrix wrote that their IT supplier’s security team had phoned to advise shutting their NetScalers down immediately, without giving details. Others in the thread said their organizations had done the same. Where the suppliers’ warning came from has not been established.

Because the flaws were exploited before a fix was public, installing the update will not show whether an attacker got in first.

In 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands’ National Cyber Security Centre said that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.

Citrix’s existing guidance for a suspected NetScaler compromise says to:

  • Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
  • Isolate the appliance from the network.
  • Change every service account password and secret stored on it, reset the passwords of users who signed in through it, and revoke its certificates and private keys.
  • Keep the management interface off the internet. “The NetScaler Management Services should never be exposed to the public internet,” the guidance says.

The Dutch agency’s 2025 check scripts, which cover a live appliance, core dumps, and full NetScaler images, are a further option, with limits.

The README for the live-appliance script says it looks for files that indicate compromise, is not specific to one vulnerability, and comes with no guarantee of effectiveness. The code was last updated in September 2025.

The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.


Source: thehackernews.com…

We will be happy to hear your thoughts

Leave a reply

Forlifedeals
Logo
Compare items
  • Total (0)
Compare
0