# What happened Citrix published a security bulletin on 27 September 2026 that fixes eight vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of the flaws are critical zero‑day remote code execution (RCE) bugs that Citrix says have been exploited on unpatched deployments.
# The two most urgent flaws
- CVE-2026-88771: An improper input validation vulnerability that allows an unauthenticated attacker to execute arbitrary commands. It affects NetScaler ADC and NetScaler Gateway deployments with the default configuration. Citrix assigns a high severity rating (CVSS 9.5 in reporting).
Citrix stated that exploitation of these two CVEs on unpatched NetScaler deployments has been observed.
# Other critical issue to note
- CVE-2026-88773: A critical HTTP request smuggling vulnerability present when HTTP configuration is enabled on NetScaler ADC or Gateway (reported CVSS 9.3).
# The remaining five CVEs in the bulletin
- CVE-2026-88775, CVE-2026-88776, CVE-2026-88777: Memory overflow vulnerabilities that may cause unpredictable behavior or denial of service (each CVSS 8.8).
- CVE-2026-88778: TCP Initial Sequence Number prediction flaw (CVSS 8.8).
# Scope and who must act This bulletin applies to customer‑managed Citrix NetScaler ADC and Citrix NetScaler Gateway appliances. Citrix said Cloud Software Group will upgrade Citrix‑managed cloud services and Citrix‑managed Adaptive Authentication with the necessary fixes.
# External advisories and response
- Centre (ACSC) issued a critical alert urging organizations to patch.
- Agency (CISA) ordered federal agencies to apply patches by 30 September 2026.
- Reports indicate national authorities such as the Dutch NCSC notified local organizations.
Before the official bulletin, third‑party researchers and some administrators reported active exploitation and took appliances offline while awaiting patches.
# Immediate actions for operators
- Apply the Citrix updates for NetScaler ADC and NetScaler Gateway immediately to cover CVE-2026-88771 and CVE-2026-88772.
# Context and follow‑up The report does not attribute the observed exploitation to a specific actor. Past incidents in 2025 involved a China‑linked intrusion (Salt Typhoon) targeting a Citrix zero day, but the current bulletin does not tie these new incidents to that actor. Monitor vendor advisories and agency notices for indicator updates and follow up on forensic guidance if you detect suspicious activity.
# Bottom line Two high‑severity NetScaler zero days enabling RCE have been actively exploited. Apply Citrix's published updates now, follow emergency network controls if you cannot patch immediately, and check guidance issued by national cyber agencies for required deadlines and additional mitigations.