Citrix Confirms Two NetScaler Zero-Days Were Exploited Before Patches Existed
An emergency bulletin covering eight vulnerabilities in Citrix's NetScaler ADC and Gateway appliances confirms that two of them, both scored 9.5 out of 10 in severity, were already being used against unpatched systems, according to Citrix and independent researchers.
Citrix Systems has confirmed that two previously unknown vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances were being actively exploited by attackers before any patch existed, prompting an emergency security bulletin that researchers say should be treated as evidence of an active breach on some networks, not a routine software update.
The company published security bulletin CTX697096 on Sept. 27, disclosing eight vulnerabilities in NetScaler ADC and Gateway and confirming that two of them had already been weaponized against appliances running with no mitigations in place. Both flaws require no authentication and no unusual configuration to trigger, which is what pushed them to the top of the company's severity scale.
The numbers
CVE-2026-88771 is an improper input-validation flaw that lets an unauthenticated attacker execute arbitrary commands on any NetScaler ADC or Gateway appliance in its default configuration, with no optional feature needed to expose it. CVE-2026-88772 is a memory-overflow bug that can trigger remote code execution or a denial-of-service condition when DTLS is enabled, a setting turned on by default for VPN virtual servers, one of the most common ways NetScaler is deployed. Both carry a CVSS score of 9.5 out of 10. Citrix's bulletin states plainly that exploitation of both vulnerabilities has been observed on unmitigated deployments. The remaining six flaws disclosed in the same bulletin, covering HTTP request smuggling, policy bypass and TCP sequence-number prediction among other issues, score lower but are being shipped in the same patch cycle.
How the exploitation came to light
NetScaler appliances sit at the edge of corporate networks, handling load balancing, VPN access and application delivery, which makes a working exploit against one unusually valuable: it can hand an intruder a foothold inside an organization without a single phishing email or stolen password. Citrix's networking products have been targeted by both nation-state and ransomware-linked hacking crews repeatedly since 2023, and the company has issued emergency fixes for exploited NetScaler bugs in each of the past several years.
This round surfaced when the security research firm watchTowr published a public FAQ describing signs of NetScaler compromise across its client base on Sept. 26, a day ahead of Citrix's own advisory, based on forensic work that pointed to live exploitation rather than a lab-only bug. According to reporting that traced the disclosure timeline, IT suppliers and at least one national cybersecurity agency had privately urged organizations to take NetScaler devices offline over the preceding weekend, before Citrix had assigned CVE identifiers or issued public guidance. That sequence, a private warning circulating among incident responders days ahead of a public bulletin, has become a familiar pattern with edge-networking appliances, where a working exploit can spread among intrusion sets before a vendor has finished drafting an advisory.
NetScaler's exploitation history in recent years includes several incidents that were each described at the time as among the most severe of the year for enterprise networking gear:
- A 2023 flaw dubbed "Citrix Bleed" that let attackers hijack authenticated sessions and was used against government and financial-sector targets before a fix was widely deployed.
- A follow-on 2025 memory-overflow bug, sometimes referred to by researchers as "Citrix Bleed 2," that similarly saw exploitation before patches were installed across a large share of internet-facing devices.
- Multiple lower-profile NetScaler advisories in the intervening months that CISA added to its Known Exploited Vulnerabilities catalog, each requiring federal civilian agencies to patch on an accelerated timeline.
Researchers say the recurrence is less a reflection of unusually sloppy code than of how attractive the product category is: any vulnerability in an appliance that terminates VPN connections and sits directly on the public internet is close to guaranteed to be probed by opportunistic scanners within days of disclosure, regardless of the vendor.
Who is affected
The exposure covers customer-managed NetScaler ADC and Gateway instances running versions earlier than 14.1-73.37 and 13.1-64.23, along with specific NetScaler ADC FIPS builds and Secure Private Access hybrid deployments. Citrix said the bulletin applies only to appliances that customers operate themselves rather than to its cloud-hosted service. Because NetScaler is widely used by banks, government agencies, universities and large enterprises to manage remote access, the population of potentially exposed organizations is large and spread across sectors and countries, and accounts of the warning reaching administrators describe it circulating well beyond any single industry before the public bulletin appeared.
Reaction
watchTowr's advisory framed the exploitation as neither isolated nor speculative.
"Citrix states it has observed exploitation of both vulnerabilities on unmitigated NetScaler deployments, and CISA reports that threat actors are exploiting them globally," the firm wrote in its public FAQ on the flaws.
Citrix's own guidance goes further than a typical patch notice. Because forensic evidence of a prior compromise on a NetScaler device can be erased simply by installing the update, the company and outside researchers are telling administrators to check for indicators of compromise and preserve logs and other forensic evidence first, and only then apply the fix, rather than patching immediately and hoping nothing was missed. The recommended follow-up steps include isolating affected appliances, resetting service-account passwords and certificates, and revoking any credentials that may have been exposed to a compromised device during the window before patches were available.
What happens next
Citrix has shipped fixed builds, NetScaler ADC and Gateway versions 14.1-73.37 and 13.1-64.23 or later, and is urging customers to install them immediately or, where that is not immediately feasible, to cut the appliance's exposure to the open internet in the meantime. The bulletin offers no interim workaround for organizations that cannot patch right away, meaning delay carries direct risk rather than a temporary safety net.
Security teams are expected to spend the coming days working through NetScaler logs for signs of intrusion that predate the public disclosure, since both watchTowr's findings and Citrix's own statement describe exploitation that began before a patch, and in some cases before any public acknowledgment, existed. Incident responders have flagged the same pattern in earlier NetScaler bugs: attackers who gained access before a fix shipped can retain it after patching unless the appliance is separately checked for backdoors, web shells or stolen session tokens, which is why the forensic-first approach is being emphasized this time rather than treated as an optional precaution.
Citrix — Security Bulletin CTX697096: NetScaler ADC and Gateway Vulnerabilities
watchTowr — Citrix NetScaler Zero-Day Vulnerabilities FAQ
BleepingComputer — Citrix confirms two NetScaler RCE zero-days exploited in attacks
The Hacker News — Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

ShinyHunters revives Oracle PeopleSoft attacks with a one-character firewall bypass
OpenAI still probing scope of rogue AI agent incidents after image leak
Jury orders Apple to pay $5.7 billion in largest patent verdict in U.S. history
