Published Tuesday, September 29, 2026 at 12:01 AM PT

BLUF: Citrix has released patches for two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway that are actively being exploited in the wild. Organizations running unpatched NetScaler infrastructure face immediate risk of full system compromise. Apply patches without delay; affected systems should be considered compromised until verified patched and audited.
DETAILS:
- Vulnerability: CVE-2026-88771 and CVE-2026-88772 are critical RCE flaws in Citrix NetScaler ADC and NetScaler Gateway; no authentication required.
- Active Exploitation: Both zero-days confirmed under active, widespread exploitation globally for weeks prior to patch release.
- Delayed Disclosure: Unofficial warnings circulated over a weekend before Citrix’s official advisory, indicating breach of embargoed disclosure and leaving many customers unaware until late in the exploitation window.
- Patch Availability: Citrix has released patches; CISA issued urgent directive to U.S. government agencies to patch immediately.
- Scope: NetScaler is pervasive in enterprise, financial, and government networks as a primary load balancer and gateway; exploitation gives attackers direct access to internal systems.
IMPACT:
Organizations with unpatched NetScaler ADC or Gateway instances are exposed to remote attackers gaining unauthenticated code execution, leading to:
- Complete system takeover (attacker code execution as system user)
- Lateral movement into internal networks
- Data exfiltration and persistent backdoors
- Disruption of critical services (NetScaler often gates all traffic)
RECOMMENDED ACTIONS (Priority Order):
- Inventory NetScaler ADC and Gateway instances immediately; determine patch status.
- Patch now β apply Citrix-released fixes to all NetScaler infrastructure without delay. Do not wait for change windows if exploitation risk is high.
- Assume breach: Systems unpatched during the exploitation window should be considered compromised; conduct full audit of authentication logs, configuration changes, and data access for the past weeks.
- Network monitoring: Enable heightened logging and detection for unusual outbound connections, privilege escalation, or lateral movement from NetScaler systems.
- Stakeholders: Notify incident response, security leadership, and business owners of the risk and patch timeline immediately.
SOURCES:
- CyberScoop, BleepingComputer, The Hacker News, SecurityWeek, SecurityAffairs, Help Net Security, CSO Online, SOC Prime, news4hackers
Recent high-severity events at publish time:

