Citrix Confirms Two Actively Exploited NetScaler Zero-Day RCE Flaws
Want more insights like this?
Citrix has patched two actively exploited flaws in NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5 on the v4.0 scale and both exploitable without authentication. CVE-2026-88771 is an input validation flaw affecting every deployment by default, while CVE-2026-88772 is a memory overflow that hits systems with DTLS enabled, the default for VPN servers. Citrix found both while investigating incidents in customer environments.
CISA added both to its Known Exploited Vulnerabilities catalog on September 27, the day the patches shipped. Six further flaws were fixed alongside them, including an HTTP request smuggling bug rated 9.3. The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS/NDcPP. Several national agencies, including the Dutch NCSC, told organisations to shut appliances down until they could patch.
Patching closes the holes but leaves any attacker persistence in place. Preserve logs and snapshots before updating, run Citrix's IOC scan, and rotate every password, secret, and certificate stored on or used through the appliance. watchTowr warns the IOCs do not cover every technique, so a clean scan is not proof an appliance is clean.
Source: Cyber Security News