Citrix patches two exploited NetScaler zero-days after silent weekend
CVE-2026-88771 affects NetScaler appliances in their default configuration, the kind of vulnerability that doesn't need a niche deployment to bite.
TL;DR
Citrix disclosed two actively exploited zero-days (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway on Sunday, nearly two days after unconfirmed warnings began circulating among CERTs, insurers, and researchers. Both are rated 9.5 and enable remote code execution. CVE-2026-88771, a command-injection flaw, works against NetScaler appliances in default configuration with a publicly available proof-of-concept. CISA added both to its Known Exploited Vulnerabilities catalog Sunday. Citrix didn't say how many customers were compromised and did not directly address the delay between the first reports and its public disclosure.
Citrix published a security advisory Sunday disclosing two actively exploited zero-days (CVE-2026-88771 and CVE-2026-88772) along with patches and six additional defects. By the time the advisory landed, nearly two days of unofficial warnings had already rippled through CERTs, advisory firms, insurers, and researchers. For some NetScaler customers, the warning came too late, though the full scope of compromise remains unknown.
"The information vacuum was most striking," Ben Harris, founder and CEO at watchTowr, told CyberScoop. "Customers were receiving warnings through unofficial channels while Citrix remained publicly silent." He added: "Citrix could have warned customers that active exploitation was occurring and provided immediate defensive guidance without disclosing technical details that would help attackers. When active exploitation is underway, hours matter."
Citrix did not directly answer questions about the communication delay. In a prepared statement, the company said it "immediately" developed and released updated software upon identifying the vulnerabilities.
Both zero-days carry a 9.5 CVSS rating. CVE-2026-88771 is a command-injection vulnerability that researchers flagged as especially concerning: it works against NetScaler appliances in default configuration, meaning a broad pool of potential targets, and a proof-of-concept exploit is publicly available. Palo Alto Networks said it identified more than 50,000 publicly exposed NetScaler devices potentially vulnerable to both flaws as of Sunday. GreyNoise observed the earliest known exploitation attempt on Sept. 24, though researchers warn attacks likely began earlier.
What the administrator does Monday
CISA added both CVEs to its Known Exploited Vulnerabilities catalog Sunday and urged users to review Citrix's advisory. The agency recommends checking for indicators of compromise before patching, since applying updates may destroy forensic evidence. Citrix is making generic IoCs available through NetScaler Console. CISA's alert also references Citrix's previously published guidance for customers who suspect compromise, a document worth having open alongside the patch deployment plan.
This marks the fifth time in 2026 that Citrix has appeared on the KEV catalog. The NetScaler product line has been a recurring target: CISA has listed Citrix vulnerabilities 26 times since late 2021.
Published ·Deep Fathom