← Home
CYBERSECURITY

Citrix Confirms Active Exploitation of Two NetScaler Zero-Day Flaws

October 4, 2026 Lawrence Abrams

Attackers Targeting Unpatched Enterprise Gateways

Citrix has officially verified that two critical remote code execution vulnerabilities in its NetScaler platform are under active attack. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, allow unauthorized users to execute arbitrary code on affected systems. This confirmation follows recent reports of widespread exploitation attempts targeting enterprise infrastructure globally.

The company stated that both vulnerabilities permit attackers to gain full control over the device without prior authentication. These zero-day flaws represent a significant security risk for organizations relying on NetScaler for load balancing and application delivery. Citrix emphasized that patches are available to mitigate the immediate threat to network stability.

Security researchers observed the initial exploitation waves earlier this month. Attackers leveraged these specific code execution paths to deploy malicious payloads on exposed servers. The vulnerabilities reside in core components of the NetScaler appliance, making them difficult to isolate through standard configuration changes alone. Organizations that delayed their update cycles faced the highest probability of compromise during this period.

How Should IT Teams Prioritize These Fixes?

Citrix noted that the attacks often resulted in persistent access, allowing threat actors to move laterally within internal networks. The vendor highlighted that successful exploitation typically leads to system crashes or complete takeover of administrative privileges. This behavior aligns with common tactics used by advanced persistent threat groups seeking long-term footholds in corporate environments.

Immediate action is required for all administrators managing NetScaler instances. Citrix recommends applying the latest cumulative updates to address both CVE-2026-88771 and CVE-2026-88772 simultaneously. Administrators should verify patch levels across all virtual appliances and physical hardware units. Temporary mitigations may help reduce exposure but do not replace the need for permanent code fixes.

Network teams must audit their external-facing gateways to identify any unpatched devices. Logging and monitoring capabilities should be enhanced to detect unusual traffic patterns associated with these exploits. The vendor advises checking for signs of previous intrusion, such as unexpected user accounts or modified system files, even after applying patches.

Frequently Asked Questions

Are both vulnerabilities fixed in the same update? Yes, Citrix released a single security bulletin addressing both CVE-2026-88771 and CVE-2026-88772. Installing the latest recommended version ensures protection against both remote code execution flaws.

Do temporary workarounds stop the attacks completely? Temporary configurations can reduce the attack surface but do not eliminate the underlying code defects. Organizations should treat workarounds as short-term measures while preparing to install the official software patches.

Which versions of NetScaler are most at risk? All versions of NetScaler Gateway and NetScaler ADC that lack the recent security updates are vulnerable. Older releases require backported fixes, while newer versions receive the standard cumulative upgrade.

Read full article on Tech Site News →