Tech News

Citrix Confirms Critical Zero-Days in NetScaler After Urgent Shutdown Warnings

A phone call, no technical details, and one single instruction: shut down NetScaler immediately. That may be what you experienced this weekend, before Citrix confirmed active exploitation of two critical zero-day flaws in NetScaler ADC and NetScaler Gateway. Here’s what you need to know.

It all started on Reddit late last week. Citrix admins received a clear instruction from their service provider or security team: they had to take the appliances offline as soon as possible. "We received a call from our managed service provider's security team, they couldn't provide details, but they advised us to shut down our NetScaler immediately", one of them said. Others mentioned contacts from CERT teams.

The panic appears to have stemmed from a pre-notification issued by the Dutch NCSC to organizations in the Netherlands. In that notice, the agency referenced two vulnerabilities that each allow remote code execution, identified by Citrix during investigations into incidents at customer environments.

For IT teams, Citrix NetScaler ADC and NetScaler Gateway can feel like a nightmare... Between CitrixBleed 2 in June 2025, the CVE-2025-7775 zero-day already exploited in attacks in August 2025, and the CVE-2026-19490 flaw I covered last month, critical security alerts keep piling up.

CVE-2026-88771 and CVE-2026-88772: two critical flaws already exploited

On September 27, 2026, Citrix finally published a security bulletin about these new zero-day security flaws. In fact, the bulletin refers to 8 vulnerabilities, including two that have been exploited as zero-days. Both carry a CVSS 4.0 score of 9.5 out of 10:

  • CVE-2026-88771: improper input validation allows an unauthenticated attacker to run arbitrary commands. This is the most concerning issue because it affects all NetScaler ADC and NetScaler Gateway deployments, including default configurations, with no special feature enabled.
  • CVE-2026-88772: a memory overflow can lead to remote code execution or a denial of service. DTLS must be enabled... which is the default on VPN virtual servers. In other words, a NetScaler Gateway instance is vulnerable here if DTLS has not been explicitly disabled.

"Exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unpatched NetScaler deployments," Citrix notes. The vendor says nothing about the scale of the attacks or who is behind them. For its part, CISA added both flaws to its KEV catalog the same day and said in a dedicated alert that it had received reports confirming active exploitation worldwide.

A very serious live alert. And if attackers are so interested in these platforms, it is because NetScaler appliances are usually exposed to the Internet to provide remote access to internal resources. Compromising this kind of equipment gives an attacker access to a company network.

How can you protect yourself?

Here are the versions that include the security fixes:

  • NetScaler ADC and NetScaler Gateway 14.1: 14.1-73.37 and later.
  • NetScaler ADC and NetScaler Gateway 13.1: 13.1-64.23 and later.
  • NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS and later.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.279 and later.

Warning: the builds released in August to fix CVE-2026-19490 (14.1-73.32 and 13.1-63.21) do not protect you against these new security flaws. So if you already updated your appliance last month, you need to do it again. Also, a quick note: this August flaw was not being exploited at the time it was disclosed, but it has since been added to the CISA KEV catalog.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.