
Critical Citrix NetScaler Zero-Day Exploits Confirmed Under Active Attack
CISA has added two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog. Threat actors are actively leveraging these flaws for remote code execution.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-88771, CVE-2026-88772
- Source:
- CISA / Citrix / watchTowr
- Read Time:
- 4 min
Executive Summary
On September 27, 2026, Citrix officially released security patches for two critical zero-day vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, following reports of active exploitation in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) has since added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation for federal agencies and urging private sector organizations to prioritize patching.
Threat Analysis
The vulnerabilities were initially identified by security firm watchTowr, which observed active exploitation attempts prior to the vendor's official disclosure. The threat actors appear to be targeting edge infrastructure to gain initial access to corporate networks. By exploiting these flaws, attackers can bypass authentication and execute arbitrary code, effectively compromising the integrity of the NetScaler appliances that serve as critical gateways for enterprise traffic.
Technical Details
CVE-2026-88771 and CVE-2026-88772 are both classified as critical vulnerabilities that allow for remote code execution (RCE). While specific technical exploit chains remain under investigation, the nature of these flaws suggests they reside within the management and gateway interfaces of the NetScaler ADC and Gateway products. Citrix has released fixes in versions 14.1-73.37 and 13.1-64.23 to address these security gaps. Organizations are advised to verify their current firmware versions against these releases immediately.
Attribution Assessment
At this time, specific attribution to a known Advanced Persistent Threat (APT) group has not been confirmed. However, the sophistication required to weaponize these zero-days suggests the involvement of well-resourced threat actors, likely nation-state aligned groups or high-tier cybercriminal syndicates specializing in initial access brokerage and corporate espionage.
Implications
The exploitation of NetScaler appliances poses a severe risk to organizational security. Because these devices sit at the network perimeter, a successful compromise provides attackers with a foothold to move laterally, exfiltrate sensitive data, or deploy ransomware. The rapid addition of these flaws to the CISA KEV catalog underscores the high probability of widespread, automated exploitation by opportunistic threat actors.
Recommendations
- Immediate Patching: Organizations must upgrade all affected Citrix NetScaler ADC and Gateway appliances to the patched versions (14.1-73.37 or 13.1-64.23) without delay.
- Forensic Review: Conduct a thorough review of system logs for indicators of compromise (IoCs), specifically looking for unauthorized administrative access or anomalous outbound traffic from the appliances.
- Network Segmentation: Ensure that management interfaces for network appliances are not exposed to the public internet and are restricted to trusted internal management subnets.
- Monitoring: Implement enhanced monitoring for the affected devices to detect any post-exploitation activity or persistence mechanisms.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Citrix NetScaler Zero-Day Exploits Confirmed in Active Global Campaigns

ShinyHunters Bypass WAF Protections to Resume Exploitation of Oracle PeopleSoft Zero-Day

