Citrix Confirms Two Actively Exploited NetScaler Zero-Day Flaws

Citrix confirms that two critical remote code execution vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in attacks. The company releases security updates in bulletin CTX697096 to address the flaws, which researchers and national cybersecurity agencies privately flag as dangerous zero-days over the weekend.

NetScaler appliances make attractive targets because organizations typically deploy them as internet-facing edge devices that provide remote access and application delivery for internal networks. Compromising one gives attackers an initial foothold at the network perimeter and a potential path to internal systems without ever touching an endpoint inside the organization. CVE-2026-88771 stems from improper input validation and allows an unauthenticated attacker to execute arbitrary commands, earning a severity score of 9.5.

Word of the exploitation first spreads when administrators report on Reddit that IT suppliers, law enforcement, CERTs, and national cybersecurity agencies urge them to shut down their NetScaler devices immediately. Security firm watchTowr later publicly warns that it is reacting to credible reports of unpatched NetScaler RCE vulnerabilities circulating in the wild, before Citrix officially confirms the flaws and ships patches.

Read More at the original source →