
Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances
Citrix has issued emergency patches for two critical RCE zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, following confirmed in-the-wild exploitation. CISA has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging immediate remediation.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-88771, CVE-2026-88772
- Source:
- Rapid7
- Read Time:
- 4 min
Executive Summary
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, two of which are critical remote code execution (RCE) zero-days currently being exploited in the wild. Tracked as CVE-2026-88771 and CVE-2026-88772, these vulnerabilities carry a CVSS score of 9.5 and allow unauthenticated attackers to gain full control over vulnerable appliances. Organizations are advised to apply the emergency patches immediately.
Threat Analysis
Threat actors are actively scanning for and compromising exposed NetScaler appliances globally. Intelligence reports indicate that the exploitation chain is being used for initial access, followed by the deployment of persistent webshells, credential harvesting, and lateral movement within internal networks. The speed at which these vulnerabilities were weaponized suggests a sophisticated actor capable of rapid exploit development following the discovery of the underlying flaws.
Technical Details
Both CVE-2026-88771 and CVE-2026-88772 are critical RCE vulnerabilities. While specific exploit primitives are still being analyzed, they allow for remote code execution without user interaction. The vulnerabilities are part of a larger security bulletin (CTX697096) that also addresses HTTP request smuggling, denial-of-service (DoS), and security bypass issues. The RCE flaws specifically target the management interface of the appliances, bypassing standard authentication mechanisms.
Attribution Assessment
While no specific APT group has claimed responsibility, the nature of the targeting—focusing on edge infrastructure—is consistent with state-sponsored espionage actors. The rapid weaponization of these zero-days suggests a well-resourced group with advanced research capabilities, likely aiming to establish long-term persistence in high-value government and corporate networks.
Implications
Successful exploitation grants attackers a foothold in the perimeter of the victim's network. Given that NetScaler appliances often sit at the edge of the network, this provides an ideal vantage point for intercepting traffic, stealing session tokens, and pivoting into sensitive internal segments. The risk of data exfiltration and ransomware deployment is extremely high for unpatched systems.
Recommendations
- Immediately apply the security updates provided by Citrix for all NetScaler ADC and Gateway instances. 2. Conduct a thorough forensic review of appliance logs for signs of unauthorized access or the presence of unexpected webshells. 3. Reset all administrative credentials and rotate API keys associated with the affected appliances. 4. Restrict management interface access to trusted IP addresses only.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



