Citrix confirmed on September 27 that two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway products have been exploited in the wild, both allowing remote code execution. The company released patches for the two flaws along with six additional vulnerabilities. One of the exploited bugs affects every deployment running a vulnerable version, even those using default settings, while the other impacts appliances with a commonly enabled feature.

The two exploited vulnerabilities carry identical severity ratings of 9.5 under the CVSS v4 scale. CVE-2026-88771 stems from improper input validation and lets an unauthenticated attacker execute arbitrary commands on all NetScaler ADC and NetScaler Gateway deployments without requiring any additional feature to be turned on. CVE-2026-88772 is a memory overflow that can trigger remote code execution or denial-of-service and affects appliances with DTLS enabled—a setting turned on by default for VPN virtual servers, meaning NetScaler Gateway installations are vulnerable unless administrators explicitly disabled it. The company's bulletin arrived one day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited and after some administrators reported taking appliances offline. NetScaler ADC and NetScaler Gateway sit at the perimeter of enterprise networks, handling VPN and remote access, load balancing, and user authentication. Citrix listed no workaround for either exploited flaw and provided no indicators of compromise. The bulletin represents the company's first public notice of the vulnerabilities, confirming both were attacked before a fix became available.

"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix stated in its bulletin. The company did not disclose how widespread the exploitation has been, which threat actors are responsible, or when the attacks began. Fixes are available in NetScaler ADC and NetScaler Gateway versions 14.1-73.37 and 13.1-64.23, with Citrix urging affected customers to install the updates immediately. The 13.1 patch came even though that branch reached End of Maintenance on September 15 under the company's release schedule. Appliances running 14.1-73.32 and 13.1-63.21—the builds that patched the exploited authentication bypass CVE-2026-19490 in August—fall within the affected range and require the new update. The six other flaws, which the bulletin does not list as exploited, include an HTTP request smuggling vulnerability, a policy bypass, three separate memory overflows affecting different server configurations, and a TCP Initial Sequence Number prediction flaw.

Because the flaws were exploited before a fix became public, installing the update won't reveal whether an attacker gained access first. Citrix's existing guidance for a suspected NetScaler compromise tells administrators to preserve evidence first—including snapshots, logs, technical support bundles, and core dumps—then isolate the appliance from the network, change every service account password and secret stored on it, reset passwords for users who signed in through it, and revoke its certificates and private keys. The company emphasizes that NetScaler Management Services should never be exposed to the public internet. As a further option, the Netherlands' National Cyber Security Centre released check scripts in 2025 after a NetScaler zero-day was exploited against Dutch organizations, though the README notes the scripts look for files indicating compromise, aren't specific to one vulnerability, and come with no guarantee of effectiveness. Organizations that delay patching risk giving attackers a foothold at the network edge, where these appliances control access to internal resources and user authentication. For enterprises that have already applied the update, the harder work begins: determining whether attackers exploited the window before the patch and, if so, what access they gained and whether they still hold it.