Skip to main content
QUIETLYTIC
Active exploitation

Two Citrix NetScaler zero-days under active attack, CISA and NCSC warn

CISA and the UK NCSC confirm attackers are exploiting two critical NetScaler ADC and Gateway flaws as zero-days. Check for compromise, then patch by 30 September.

Category
Active exploitation
Severity
Critical
CVEs
CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778

Attackers around the world are exploiting two previously unknown flaws in Citrix NetScaler ADC and NetScaler Gateway, the appliances many organisations use as their remote-access front door and application load balancer. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog on 27 September, and the UK’s National Cyber Security Centre followed a day later with its own alert urging British organisations to act. Each flaw can hand an unauthenticated attacker code execution on its own, and US federal civilian agencies have been given until 30 September to deal with them.

The pair are part of a batch of eight NetScaler vulnerabilities that Citrix disclosed at the same time. Only two are confirmed as exploited, but all eight are fixed by the same releases.

The two exploited flaws

CVE-2026-88771 is an input validation failure (CWE-20). According to its NVD record, a remote attacker with no credentials can use it to run arbitrary commands on an affected appliance. The CVSS 4.0 base score is 9.5, critical, with low attack complexity, no privileges and no user interaction required. The vector does note an attack requirement, meaning some condition on the target must be present for the attack to work; neither agency spells out which configurations meet it.

CVE-2026-88772 is a memory-safety bug (CWE-119, writing or reading outside a buffer’s bounds). The NVD entry says it can lead to either remote code execution or denial of service. It also scores 9.5 under CVSS 4.0, though its vector rates attack complexity as high, which usually means success depends on factors the attacker does not fully control. That is little comfort once a technique is circulating.

CISA describes both as critical zero-days that can each independently lead to remote code execution, and says reports it has received and threat intelligence from partners confirm exploitation is happening globally. The NCSC states it is still working to understand the effect on UK organisations. Neither agency has named a threat actor, and neither says whether the activity is linked to ransomware.

The other six fixes in the bulletin

The remaining CVEs, which neither agency reports as exploited, cover a spread of weaknesses:

  • CVE-2026-88773: HTTP request smuggling, where the appliance and a back end disagree on how a request is framed, potentially letting an attacker slip past security controls.
  • CVE-2026-88774: a URL-based expression handling flaw that can bypass a feature policy.
  • CVE-2026-88775, CVE-2026-88776 and CVE-2026-88777: three memory overflow bugs that can cause erratic behaviour or knock the appliance offline.
  • CVE-2026-88778: a predictable-value weakness that could let an attacker affect integrity or availability.

Request smuggling on an internet-facing gateway deserves more attention than its lack of a KEV listing suggests, because bypassing controls on the device that fronts every other application can open doors further in.

Which appliances are affected

Customer-managed NetScaler ADC and NetScaler Gateway deployments are in scope. Citrix-hosted cloud services are not listed by either agency. Per the NCSC and the NVD records, the affected supported builds are:

Product line Vulnerable before
NetScaler ADC and Gateway 14.1 14.1-73.37
NetScaler ADC and Gateway 13.1 13.1-64.23
NetScaler ADC 14.1 FIPS 14.1-73.37 FIPS
NetScaler ADC 13.1 FIPS and NDcPP 13.1-37.279

Any appliance on an older, end-of-life branch sits outside this list, which should not be read as safe: the agencies list only supported builds, so treat older branches as exposed until they are upgraded to a supported, fixed line.

NetScaler Gateway is by design reachable from the internet, so exposure is broad. Any organisation that runs it as its VPN or published-application portal should assume its appliances are being probed, and managed service providers operating NetScaler for several customers should treat this as a fleet-wide problem.

Why patching comes second

Both agencies stress an order of operations that runs against instinct. Because these flaws were exploited before a fix existed, an appliance that has been online since before 27 September may already be compromised, and applying the update can wipe the evidence needed to tell. CISA explicitly advises checking for signs of compromise before patching and preserving forensic evidence first if anything looks wrong. KEV entries for both CVEs also carry CISA’s forensic triage requirement, and Binding Operational Directive 26-04 sets expectations for when federal agencies must check whether a system was compromised before the patch went on, not just update it.

The NCSC goes further, recommending that where practical, organisations take the affected appliance out of service and stand up a fresh, fully patched replacement rather than patching in place.

What to do now

  1. Inventory every NetScaler ADC and Gateway instance and record its exact build, including FIPS and NDcPP units and any lab or disaster-recovery appliances that are easy to forget.
  2. Reduce exposure immediately on anything still vulnerable. The NCSC suggests upstream firewall rules, disabling the vulnerable component, or limiting access to the organisation’s own address ranges while the rest of the work happens.
  3. Hunt before you patch. Use the indicators of compromise Citrix has published through NetScaler Console and its security bulletin. Look for unexpected files, new accounts, altered configuration and unusual outbound connections from the appliance. NetScaler Console’s file integrity monitoring can help flag changed files on managed instances.
  4. Preserve evidence if anything is found. Capture disk and memory images and logs before updating, and follow Citrix’s guidance for suspected compromise. UK organisations should report incidents to the NCSC.
  5. Upgrade to the fixed builds listed above, or rebuild on them, then confirm the running version on every node of each HA pair or cluster.
  6. Assume credential theft on any compromised unit. Gateways handle user sessions and often hold service account secrets for back-end integrations. Rotate those, terminate active sessions, and review access logs for the applications behind the gateway.
  7. Keep watching. The NCSC advises monitoring the Citrix security bulletin for updates and continuing threat hunting after the update.

What remains unclear

There is no public detail yet on who is behind the exploitation, how many appliances have been hit, or which sectors are the main targets. Neither agency has said when exploitation began, which matters for how far back log reviews should reach; the safest assumption is to review everything your retention allows. Exploitation status in this article reflects CISA’s and the NCSC’s findings; Quietlytic has not independently observed the activity.

Organisations outside the US federal government are not bound by the 30 September deadline. Given that both flaws need no login and sit on internet-facing devices, it is a sensible deadline to adopt anyway.

Source: Cybersecurity and Infrastructure Security Agency (CISA)

Contains public sector information licensed under the Open Government Licence v3.0 (UK NCSC)

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources

  1. CISA — Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (27 September 2026)
  2. CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog (27 September 2026)
  3. NCSC — Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway (28 September 2026)
  4. NVD — CVE-2026-88771
  5. NVD — CVE-2026-88772

Related intelligence


Analyst tools