AIO APEX

Citrix confirms two NetScaler zero-days under active exploitation worldwide

BleepingComputer
Share:
Citrix confirms two NetScaler zero-days under active exploitation worldwide

Citrix confirmed on September 27 that two critical remote code execution vulnerabilities in its NetScaler ADC and NetScaler Gateway products are being actively exploited in attacks worldwide, and released patched builds the same day. Both flaws, tracked as CVE-2026-88771 and CVE-2026-88772, carry a CVSS v4 severity score of 9.5 out of 10. CISA added both to its Known Exploited Vulnerabilities catalog and issued an alert urging immediate patching.

The vulnerabilities first surfaced publicly on September 26, when NetScaler administrators reported being told by suppliers and security researchers to shut down their appliances entirely until a fix was available — an unusually blunt recommendation that reflected how severe the exposure was in the window before Citrix shipped a patch.

Why these two flaws are so dangerous

CVE-2026-88771 is an improper input validation vulnerability that lets an unauthenticated attacker execute arbitrary commands on the appliance. Critically, it affects every NetScaler ADC and NetScaler Gateway deployment running an affected version, including installations left at default configuration — no additional feature needs to be enabled for a device to be exposed.

CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service, but only when DTLS is enabled on the appliance. Because DTLS is turned on by default for VPN virtual servers, the vast majority of real-world NetScaler Gateway deployments meet that precondition unless an administrator has explicitly disabled it. Both flaws were disclosed as part of security bulletin CTX697096, which addressed eight vulnerabilities in total.

Why NetScaler is such a high-value target

NetScaler appliances are almost always deployed as internet-facing edge devices, sitting at the perimeter of a corporate network to handle remote access and application delivery. That positioning is exactly what makes them attractive to attackers: a successful exploit against an unauthenticated, internet-reachable appliance gives an attacker an initial foothold inside a corporate network without needing stolen credentials or a phishing email first. Security researchers who reviewed the disclosure noted that this is the same class of device — internet-facing VPN and application-delivery hardware — that has been repeatedly targeted in major enterprise breaches over the past several years, precisely because compromising the edge device bypasses most of an organization's internal defenses in one step.

What organizations need to do now

Citrix has released fixed builds addressing both vulnerabilities, and CISA's advisory sets a mandatory patching deadline for US federal agencies. For any organization running NetScaler ADC or NetScaler Gateway, the practical guidance from security researchers is direct: patch immediately, and treat any unpatched internet-facing appliance as potentially already compromised given that exploitation has been observed in the wild since before the patch was available. Organizations that cannot patch immediately should consider taking affected appliances offline, following the same guidance NetScaler administrators were given during the 48-hour window between public disclosure and the availability of a fix.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: