Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Swati KhandelwalSep 27, 2026Vulnerability / Network Security

Recently, Citrix confirmed the exploitation of two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution. The company released fixes for both vulnerabilities, along with addressing six other flaws. One of the vulnerabilities impacts every deployment on an affected version, even those in the default configuration.

The acknowledgment came shortly after a security firm, watchTowr, reported that two unpatched NetScaler RCE flaws had been exploited in the wild. Some administrators had even taken their appliances offline as a precaution. While Citrix did not explicitly confirm if the two flaws mentioned align with watchTowr’s findings, they do correspond to the reported vulnerabilities.

NetScaler ADC and NetScaler Gateway play crucial roles at the edge of enterprise networks, handling VPN and remote access, load balancing, and user authentication.

Citrix specified in its bulletin that the two vulnerabilities being exploited are:

  • CVE-2026-88771 (CVSS v4 score: 9.5) – An improper input validation flaw allowing unauthenticated attackers to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments without requiring any additional features.
  • CVE-2026-88772 (CVSS v4 score: 9.5) – A memory overflow issue leading to remote code execution or denial-of-service (DoS) attacks. This vulnerability affects appliances with DTLS enabled, which is turned on by default for VPN virtual servers, making it a threat to NetScaler Gateway unless DTLS has been explicitly disabled.

Citrix warned, \”Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,\” without providing details on the extent of exploitation or the actors involved.

The bulletin marks Citrix’s initial public disclosure of these vulnerabilities, indicating that they were exploited before a fix was made available. Unfortunately, no workarounds or compromise indicators are provided in the bulletin.

Appliances running on versions 14.1-73.32 and 13.1-63.21, which addressed the previously exploited authentication bypass vulnerability CVE-2026-19490 in August, fall within the affected range and require the latest updates.

The recommended fixes are included in the following versions, which Citrix strongly advises affected customers to install promptly:

  • NetScaler ADC and NetScaler Gateway 14.1-73.37 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-64.23 and subsequent releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later FIPS releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later FIPS and NDcPP releases

The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments. Citrix also ensures upgrades for its cloud services and Citrix-managed Adaptive Authentication.

The 13.1 fix release followed the branch’s End of Maintenance on September 15, as per Citrix’s release schedule.

Additionally, the bulletin addresses six other vulnerabilities that have not been reported as exploited, including:

  • CVE-2026-88773 (CVSS v4 score: 9.3) – An HTTP request smuggling flaw affecting appliances with specific virtual server configurations.
  • CVE-2026-88774 (CVSS v4 score: 7.0) – A policy bypass issue related to HTTP URL-based expressions.
  • CVE-2026-88775 (CVSS v4 score: 8.8) – A memory overflow vulnerability impacting certain types of virtual servers.
  • CVE-2026-88776 (CVSS v4 score: 8.8) – A memory overflow flaw affecting Oracle load balancing virtual servers.
  • CVE-2026-88777 (CVSS v4 score: 8.8) – A memory overflow vulnerability on setups with non-HTTP Layer 7 protocol features enabled.
  • CVE-2026-88778 (CVSS v4 score: 8.8) – A TCP Initial Sequence Number (ISN) prediction flaw on certain virtual servers.

watchTowr’s initial announcement on X hinted at the existence of unpatched NetScaler RCE vulnerabilities, with further updates expected from Citrix to address the situation.

Amidst the security concerns, administrators have been advised to take precautionary measures, including isolating compromised appliances and changing critical credentials stored within the systems. Stay tuned for updates as the situation develops.

For further guidance on addressing suspected compromises, refer to Citrix’s recommended steps, which emphasize evidence preservation and network isolation.

As the cybersecurity landscape evolves, it’s crucial for organizations to stay vigilant and proactive in safeguarding their systems against potential threats. Stay informed, stay secure.