Security

Citrix NetScaler: two critical zero-days that have been exploited for weeks

CVE-2026-88771 and CVE-2026-88772 allow unauthenticated remote code execution on NetScaler ADC and Gateway. Citrix released the patch on September 27, but active exploitation began weeks earlier.

Published on September 30, 2026 · The mitza.es team

Citrix confirmed on September 27, 2026, two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, its widely used load-balancing and remote VPN access products deployed across mid-size and large companies. Both were already being actively exploited before a patch existed: according to researchers who tracked them closely, the first attacks trace back to early September, weeks before the official advisory.

What CVE-2026-88771 and CVE-2026-88772 actually are

  • CVE-2026-88771: improper input validation that lets an unauthenticated attacker run arbitrary commands on the appliance. It affects every NetScaler ADC and Gateway deployment on a vulnerable version, including the default configuration.
  • CVE-2026-88772: a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which is on by default for VPN virtual servers unless explicitly disabled.

Both score 9.5 out of 10 under CVSS 4.0, close to the maximum severity rating.

The scale of the problem: over 50,000 exposed instances

A Palo Alto Networks Cortex Xpanse scan carried out on September 27, 2026, identified over 50,000 potentially vulnerable NetScaler instances accessible from the internet worldwide. CISA confirms that threat actors are actively exploiting both flaws at global scale, not just in isolated targeted attacks.

How the attack has unfolded

According to analysis from several security firms, exploitation followed a consistent pattern: unauthenticated initial access through the command-execution flaw, followed by reconnaissance of the internal environment and, in several documented cases, lateral movement into other systems on the corporate network. Attack intensity stayed sustained for weeks before a patch was available.

What to do right now if you use NetScaler

  • Update to the fixed versions Citrix published in security bulletin CTX697096 on September 27, 2026.
  • If you can't patch immediately, disable DTLS on VPN virtual servers as a partial mitigation for CVE-2026-88772.
  • Review access logs from the past few weeks, not just the past few days: exploitation started before the public advisory.
  • Assume an exposed, unpatched device may already be compromised, not just vulnerable.

Why this isn't an isolated case

It's the second major critical-infrastructure alert to be rapidly exploited in recent weeks, after the Renfe and Adif cyberattack. The pattern repeats: internet-facing remote access appliances, thousands of publicly exposed instances, and an increasingly short window between vulnerability disclosure and mass exploitation.

How to find out if your own infrastructure is exposed

You don't need to run a NetScaler to be at risk: any perimeter device, CMS or unpatched dependency is a potential way in. If you want to know what vulnerabilities your infrastructure has exposed right now, you can request a website security audit, and if you need ongoing support with patching and configuration, our IT maintenance service includes a basic security review.

Using Citrix NetScaler, or not sure if your infrastructure is exposed?

We'll send you a risk-prioritised report within 24-48 hours, no commitment.

No spam. No sales calls. Just your personalised reply.