Infosecurity Magazine iconInfosecurity MagazineSep 28, 2026 ~4 min source read

Citrix issues urgent NetScaler fixes after two critical zero-day RCEs are exploited

Citrix published updates for eight NetScaler vulnerabilities on 27 September 2026, including two critical remote‑code‑execution flaws that have been observed in the wild. Customers must apply vendor updates immediately; US federal agencies have a mandated patch deadline.

Share this story

Send the public story page.

Useful takeaways from this story.

In a bulletin on September 27 the vendor confirmed eight new flaws in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).

Enforcing AI Authority Before the Action Webinar 15:00 — 16:00, 8 October 2026 1 Experts Alarmed Over Gyazo's Breach of 490 Million Metadata Records News 21 September 2026 2 US:

The two most urgent are: CVE-2026-88771: a remote code execution (RCE) flaw due to improper input validation, enabling an unauthenticated attacker to execute arbitrary commands.

# What happened Citrix published a security bulletin on 27 September 2026 that fixes eight vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Two of the flaws are critical zero‑day remote code execution (RCE) bugs that Citrix says have been exploited on unpatched deployments.

# The two most urgent flaws

  • CVE-2026-88771: An improper input validation vulnerability that allows an unauthenticated attacker to execute arbitrary commands. It affects NetScaler ADC and NetScaler Gateway deployments with the default configuration. Citrix assigns a high severity rating (CVSS 9.5 in reporting).

Citrix stated that exploitation of these two CVEs on unpatched NetScaler deployments has been observed.

# Other critical issue to note

  • CVE-2026-88773: A critical HTTP request smuggling vulnerability present when HTTP configuration is enabled on NetScaler ADC or Gateway (reported CVSS 9.3).

# The remaining five CVEs in the bulletin

  • CVE-2026-88775, CVE-2026-88776, CVE-2026-88777: Memory overflow vulnerabilities that may cause unpredictable behavior or denial of service (each CVSS 8.8).
  • CVE-2026-88778: TCP Initial Sequence Number prediction flaw (CVSS 8.8).

# Scope and who must act This bulletin applies to customer‑managed Citrix NetScaler ADC and Citrix NetScaler Gateway appliances. Citrix said Cloud Software Group will upgrade Citrix‑managed cloud services and Citrix‑managed Adaptive Authentication with the necessary fixes.

# External advisories and response

  • Centre (ACSC) issued a critical alert urging organizations to patch.
  • Agency (CISA) ordered federal agencies to apply patches by 30 September 2026.
  • Reports indicate national authorities such as the Dutch NCSC notified local organizations.

Before the official bulletin, third‑party researchers and some administrators reported active exploitation and took appliances offline while awaiting patches.

# Immediate actions for operators

  • Apply the Citrix updates for NetScaler ADC and NetScaler Gateway immediately to cover CVE-2026-88771 and CVE-2026-88772.

# Context and follow‑up The report does not attribute the observed exploitation to a specific actor. Past incidents in 2025 involved a China‑linked intrusion (Salt Typhoon) targeting a Citrix zero day, but the current bulletin does not tie these new incidents to that actor. Monitor vendor advisories and agency notices for indicator updates and follow up on forensic guidance if you detect suspicious activity.

# Bottom line Two high‑severity NetScaler zero days enabling RCE have been actively exploited. Apply Citrix's published updates now, follow emergency network controls if you cannot patch immediately, and check guidance issued by national cyber agencies for required deadlines and additional mitigations.

More context around this story.

Citrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws (Lawrence Abrams/Bleeping...
Techmeme iconTechmemeSep 28, 2026

Citrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws (Lawrence Abrams/Bleeping...

Lawrence Abrams / BleepingComputer : Citrix confirms two critical NetScaler zero-day RCE vulnerabilities are being exploited in attacks, says it has released security updates to fix the flaws — Update: Article rewritten with official confirmation from Citrix. — Citrix has confirmed that two critical NetScaler remote co

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app