
Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally
Citrix has confirmed active, in-the-wild exploitation of two critical remote code execution zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway products.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-88771, CVE-2026-88772
- Source:
- Rapid7
- Read Time:
- 4 min
Executive Summary
On September 27, 2026, Citrix disclosed a set of eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Among these, two critical remote code execution (RCE) vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, have been confirmed as actively exploited in the wild. CISA has officially added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate patching for federal agencies and urging private sector organizations to prioritize remediation.
Threat Analysis
Threat actors are currently scanning the internet for exposed NetScaler appliances to gain initial access. Intelligence reports indicate that the exploitation of these vulnerabilities allows unauthenticated attackers to execute arbitrary code on the target device. Once initial access is achieved, attackers have been observed deploying persistent webshells, facilitating credential harvesting, and performing lateral movement within compromised enterprise networks. The speed at which these exploits were weaponized following the disclosure suggests a highly capable threat actor group, likely operating with nation-state backing or advanced cybercriminal resources.
Technical Details
Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS v4.0 score of 9.5. These vulnerabilities reside in the management interface of the NetScaler appliances. The flaws enable remote code execution without requiring user interaction or authentication. The exploitation chain typically involves sending specially crafted HTTP requests that bypass existing security filters, leading to memory corruption or command injection. The broader advisory (CTX697096) also addresses other issues, including HTTP request smuggling and security bypasses, which may be chained by attackers to escalate privileges.
Attribution Assessment
While specific attribution remains under investigation, the sophistication of the exploit and the rapid deployment across global infrastructure are characteristic of advanced persistent threat (APT) groups. The targeting of edge infrastructure—specifically load balancers and gateways—is a hallmark of espionage-focused actors seeking long-term persistence in high-value corporate and government environments.
Implications
Organizations utilizing NetScaler ADC or Gateway are at immediate risk of total system compromise. Successful exploitation grants attackers full control over the appliance, which often sits at the perimeter of the network, providing a strategic vantage point for intercepting traffic, stealing session tokens, and pivoting into internal segments. The potential for data exfiltration and ransomware deployment is extremely high.
Recommendations
- Immediate Patching: Apply the latest security updates provided by Citrix for all NetScaler ADC and Gateway appliances without delay.
- Configuration Review: Audit appliance configurations for unauthorized changes or newly created administrative accounts.
- Threat Hunting: Inspect system logs for anomalous HTTP requests, unexpected outbound connections, or the presence of unknown files in web directories.
- Network Segmentation: Restrict access to the management interface of NetScaler appliances to trusted IP addresses only.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances

Critical Citrix NetScaler Zero-Day Exploits Confirmed in Active Global Campaigns

