
Critical Citrix NetScaler Zero-Day Exploits Confirmed in Active Global Campaigns
CISA has added two critical RCE vulnerabilities in Citrix NetScaler ADC and Gateway to its KEV catalog following reports of active exploitation. Organizations are urged to patch immediately.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-88771, CVE-2026-88772
- Source:
- CISA / Citrix Security Bulletin
- Read Time:
- 4 min
Executive Summary
On September 27, 2026, Citrix officially released security patches for two critical zero-day vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and NetScaler Gateway appliances. These vulnerabilities were identified as being actively exploited in the wild prior to the release of official fixes. The Cybersecurity and Infrastructure Security Agency (CISA) has formally added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling a high risk to enterprise infrastructure worldwide.
Threat Analysis
The exploitation of these vulnerabilities was first brought to light by security researchers at watchTowr, who identified the flaws during forensic investigations of compromised environments. Threat actors have been observed chaining these vulnerabilities to bypass authentication mechanisms and achieve remote code execution (RCE) on edge appliances. By targeting the NetScaler interface, attackers gain a foothold within the internal network, facilitating lateral movement and data exfiltration. The speed at which these vulnerabilities moved from discovery to active exploitation suggests a sophisticated actor capable of rapid weaponization.
Technical Details
CVE-2026-88771 and CVE-2026-88772 are both critical-severity flaws that allow for unauthenticated remote code execution. While specific technical primitives remain under investigation, initial reports indicate that the vulnerabilities reside in the management interface of the NetScaler appliances. Attackers leverage these flaws to bypass security controls, allowing them to execute arbitrary OS commands with elevated privileges. Citrix has addressed these issues in versions 14.1-73.37 and 13.1-64.23, and administrators are advised to verify their build versions immediately.
Attribution Assessment
While no specific Advanced Persistent Threat (APT) group has been publicly named as the primary actor, the nature of the targeting—focusing on high-value network infrastructure—is consistent with state-sponsored espionage campaigns. The ability to weaponize zero-day vulnerabilities in such a short timeframe indicates a high level of technical maturity, likely pointing toward a well-resourced nation-state actor or a highly capable cybercriminal syndicate specializing in initial access brokerage.
Implications
The compromise of NetScaler appliances poses a severe risk to organizational security, as these devices often sit at the perimeter of the network, providing access to sensitive internal resources. Successful exploitation allows attackers to bypass multi-factor authentication (MFA) and gain persistent access to the corporate environment, potentially leading to ransomware deployment or long-term intellectual property theft.
Recommendations
- Immediate Patching: Organizations must upgrade all affected NetScaler ADC and Gateway appliances to the latest versions (14.1-73.37 or 13.1-64.23) without delay.
- Forensic Review: Conduct a thorough audit of appliance logs for unauthorized access or anomalous command execution patterns.
- Network Segmentation: Ensure that management interfaces for critical infrastructure are not exposed to the public internet.
- Credential Rotation: If an appliance is suspected of being compromised, rotate all administrative credentials and service account tokens immediately.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure

ShinyHunters Bypass WAF Protections to Resume Exploitation of Oracle PeopleSoft Zero-Day

