Site icon VMVirtualMachine.com

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

By Eduard Kovacs
Publication Date: 2026-09-28 07:29:00

Over the weekend, Citrix rushed out patches for two critical NetScaler zero-day vulnerabilities that have been exploited in the wild.

The company’s advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including remote code execution, HTTP request smuggling, DoS, and security bypass issues.

The two zero-days for which Citrix confirmed exploitation are tracked as CVE-2026-88771 and CVE-2026-88772. Both have a CVSS score of 9.5.

CVE-2026-88771 is a remote code execution vulnerability that can be exploited without authentication. It affects all NetScaler ADC and Gateway deployments, including those in the default configuration.

CVE-2026-88772 is a memory overflow that can be exploited for remote code execution or DoS attacks. It affects appliances with DTLS configuration enabled, which is the default setting on VPN virtual servers.

Citrix has made available indicators of compromise (IoCs).

Advertisement. Scroll to continue…