-
Citrix says attackers are already using two critical flaws in its NetScaler ADC and NetScaler Gateway products.
-
One flaw affects every NetScaler setup, including default settings, and both flaws score 9.5 out of 10.
-
Citrix has released fixed versions, and CISA has added both flaws to its list of exploited bugs.
Citrix has confirmed that attackers are actively using two serious flaws against its customers. The flaws sit in NetScaler ADC and NetScaler Gateway, two products that many companies use. Their tracking numbers are CVE-2026-88771 and CVE-2026-88772.
Both can let an attacker run code on a device from far away. That kind of access can give attackers strong control over the affected machine. Remote code execution means an attacker can run their own commands on a device without being there.
Citrix shared the news on September 27. The company published a security bulletin that covers eight flaws in NetScaler. It said it had seen attacks using CVE-2026-88771 and CVE-2026-88772.
Those attacks hit systems that had no protection in place. Only two of those eight flaws were seen in attacks. Citrix urged customers to install the available security updates as soon as possible.
Default NetScaler Setups Face Attack
CVE-2026-88771 is an input checking flaw. The product fails to check some incoming data properly. An attacker with no login can use this gap to run commands remotely. Citrix rates the flaw 9.5 out of 10 on the CVSS 4.0 scale. CVSS is a scoring system that rates how dangerous a flaw is. The scale tops out at 10, so this flaw sits near the very top.
According to the Citrix bulletin, every NetScaler ADC and NetScaler Gateway deployment is affected. That includes systems that run on their default settings. Owners do not need to switch on any extra feature or setting for the risk to apply. A device can be open to attack straight out of the box. The NIST vulnerability database also lists this flaw, and so does Tenable.
CVE-2026-88772 works in a different way. It is a memory overflow flaw. An attacker can use it to run code remotely. The same flaw can also crash a device and cut off its service.
This attack only works when DTLS is switched on. Citrix notes that DTLS is on by default for VPN virtual servers. That makes the flaw relevant to NetScaler Gateway users. Devices without DTLS do not meet the condition for CVE-2026-88772. Citrix gives this flaw the same 9.5 score on the CVSS 4.0 scale.
CISA and Other Agencies Warn of Global Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities Catalog. The agency did this because it saw evidence of active attacks.
CISA published its alert on September 27, the same day as the Citrix bulletin. Its catalog lists flaws that attackers are already using in the real world. According to CISA’s alert, partner threat intelligence shows attackers are using the flaws around the world.
Other agencies have reached the same view. The Canadian Centre for Cyber Security published an alert about the critical flaws. The alert covers CVE-2026-88771 and CVE-2026-88772 together.
Australia’s Cyber Security Centre also confirmed the global attacks. It said attackers used both flaws before patches became available, as noted in the CERT-EU advisory. CERT-EU published that advisory under the number 2026-014.
Security news sites have covered the story too. BleepingComputer and SecurityWeek both reported on the two NetScaler zero-days. A zero-day is a flaw that attackers use before a fix exists.
Fixed Versions Are Out, and Checks Are Urged
Patches are already available as of September 27, 2026. Citrix has released fixed builds for the affected products. These are not the only security issues affecting NetScaler, as covered in our story on Citrix patches six NetScaler vulnerabilities that could expose sensitive files and covering another set of vulnerabilities affecting the platform. Owners of either product should check their versions. Customers should upgrade to 14.1-73.37 or later, or 13.1-64.23 or later, depending on their setup.
Citrix also offers separate fixed builds for affected FIPS and NDcPP versions, as listed in the security bulletin. Teams that run those versions must pick the separate builds. The bulletin shows which build suits each deployment.
Agencies want organizations to look for signs of a break-in too. CERT-EU recommends updating the affected software. It also advises a compromise assessment, which means checking whether attackers already got in. The agency says this matters most for devices that face the internet.
CISA gave admins one more piece of advice. Where possible, they should look for signs of compromise before they patch. According to CISA, applying updates can change what investigators are able to see. Experts call this forensic visibility.
It means the evidence left on a device. Citrix has shared indicators of compromise through NetScaler Console. Indicators of compromise are clues that show a device may have been attacked. Those clues help teams check each affected device for signs of a break-in.
The story has therefore moved past a simple warning about coming patches. Attacks are confirmed, and fixes are ready. Organizations that run affected NetScaler devices should find their vulnerable systems first. Next, they should check those systems for signs of compromise. Then they should apply the correct Citrix updates.