DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27.

DKCISSP News DeskThe Hacker News27 Sept 2026, 9:51 pm
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

The bulletin came a day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited, and after some administrators said they had taken appliances offline.

The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27.

The fixes are in the following versions, which Citrix urged affected customers to install as soon as possible: The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments.

In 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands' National Cyber Security Centre said that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.

Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the exploited authentication bypass CVE-2026-19490 in August, fall inside the affected range and need the new update.

One of the two affects every deployment on an affected version, including those in the default configuration.

Citrix confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.

Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.

What happened

The bulletin came a day after security firm watchTowr said two unpatched NetScaler RCE flaws had been exploited, and after some administrators said they had taken appliances offline.

The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment, and will update the story if it hears back.

What changed

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27.

Who is affected

The fixes are in the following versions, which Citrix urged affected customers to install as soon as possible: The bulletin covers customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments.

In 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands' National Cyber Security Centre said that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.

Why it matters

Appliances on 14.1-73.32 and 13.1-63.21, the builds that fixed the exploited authentication bypass CVE-2026-19490 in August, fall inside the affected range and need the new update.

One of the two affects every deployment on an affected version, including those in the default configuration.

Technical details

Citrix confirmed that both flaws have been exploited in attacks against NetScaler devices as zero-days.

Before Citrix publicly disclosed the vulnerabilities, the Dutch National Cyber Security Center (NCSC-NL) reportedly sent a pre-notification to organizations in the Netherlands warning about two critical NetScaler zero-days.

The notification said Citrix discovered the vulnerabilities while investigating incidents in customer environments and identified active exploitation.

Response

Cybersecurity firm watchTowr later publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with "authoratitive sources." "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.

Citrix says the flaw affects all NetScaler ADC and NetScaler Gateway deployments, including those using the default configuration, and does not require any more feature to be enabled.

What security teams should do

The six other flaws, which the bulletin does not list as exploited, are: watchTowr's first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild.

Because the flaws were exploited before a fix was public, installing the update will not show whether an attacker got in first.

What remains unknown

Citrix did not say whether its two flaws are the ones watchTowr described, but they match that account.

It did not say how widely the flaws have been exploited, by whom, or since when.

Attribution

The Hacker News: Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27.

BleepingComputer: Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm